It was discovered that nghttp2, an implementation of the HTTP/2 protocol, could be crashed via an assertion failure. A remote attacker could exploit this to cause a DoS attack by sending a malformed frame immediately after triggering the termination path.
https://security-tracker.debian.org/tracker/DSA-6266-1
Continue reading...
https://security-tracker.debian.org/tracker/DSA-6266-1
Continue reading...

