CVE-2018-1000168 | nghttp2 up to 0.9.x/1.30.x ALTSVC Frame input validation (RHSA-2019:0366 / Nessus ID 111095)
A vulnerability classified as problematic was found in nghttp2 up to 0.9.x/1.30.x. Affected by this vulnerability is an unknown functionality of the component ALTSVC Frame Handler. The manipulation leads to improper input validation.
This vulnerability is known as CVE-2018-1000168. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.