Description
An unspecified vulnerability was found in Apache HTTP Server 2.4.17 through 2.4.23. By exploiting this vulnerability malicious users can cause denial of service. This vulnerability can be exploited remotely via crafted continuation frames in a HTTP/2 request.
Technical details
Vulnerability occurs in mod_http2 module, when the Protocols configuration (including h2/h2c) does not confine length of request header. Because of that a specially crafted request can allocate memory on the sever until limit is reached.
Original advisories
Exploitation
Public exploits exist for this vulnerability.
Related products
CVE list
- CVE-2016-8740 warning
Read more
Find out the statistics of the vulnerabilities spreading in your region on statistics.securelist.com