GLSA-201612-06 : nghttp2: Heap-use-after-free
Critical Nessus Plugin ID 95521
SynopsisThe remote Gentoo host is missing one or more security-related patches.
DescriptionThe remote host is affected by the vulnerability described in GLSA-201612-06 (nghttp2: Heap-use-after-free)
A heap-use-after-free vulnerability has been discovered in nghttp2.
Please review the CVE identifier referenced below for details.
The impact of the vulnerability is still unknown.
There is no known workaround at this time.
SolutionAll nghttp2 users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose '>=net-libs/nghttp2-1.6.0'