Name : nghttp2 Product : Fedora 22 Version : 1.7.1 Release : 1.fc22 URL : https://nghttp2.org/ Summary : Experimental HTTP/2 client, server and proxy Description : This package contains the HTTP/2 client, server and proxy programs.
CVE-2016-1544: Out of memory in nghttpd, nghttp, and libnghttp2_asio applications due to unlimited incoming HTTP header fields: https://github.com/tatsuhiro-t/nghttp2/releases/tag/v1.7.1 ------------------------------------------------------------------------------- - References:
[ 1 ] Bug #1308461 - CVE-2016-1544 nghttp2: out of memory error due to unlimited incoming HTTP header fields https://bugzilla.redhat.com/show_bug.cgi?id=1308461 ------------------------------------------------------------------------------- -
This update can be installed with the "yum" update program. Use su -c 'yum update nghttp2' at the command line. For more information, refer to "Managing Software with yum", available at https://docs.fedoraproject.org/yum/.