HTTP: Node.js Foundation nghttp2 nghttp2_frame_altsvc_free CVE-2018-1000168 Null Pointer Dereference
This signature detects attempts to exploit a known vulnerability against Node.js. Successful exploitation results in a Null Pointer dereference causing denial of service.
Extended Description
nghttp2 version >= 1.10.0 and nghttp2 = 1.31.1.
Affected Products
Nodejs node.js
References
CVE: CVE-2018-1000168
srx-branch-19.3
vsrx3bsd-19.2
srx-19.4
vsrx3bsd-19.4
srx-branch-19.4
vsrx-19.4
vsrx-19.2
srx-19.3
srx-branch-12.3
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx-12.3
vmx-19.3
srx-12.3
Nghttp2
Debian
Nodejs
5.0