KLA10907
Denial of service vulnerability in Apache HTTP Server
Обновлено: 17/06/2019
Дата обнаружения
05/12/2016
Уровень угрозы
Warning
Описание

An unspecified vulnerability was found in Apache HTTP Server 2.4.17 through 2.4.23. By exploiting this vulnerability malicious users can cause denial of service. This vulnerability can be exploited remotely via crafted continuation frames in a HTTP/2 request.


Technical details

Vulnerability occurs in mod_http2 module, when the Protocols configuration (including h2/h2c) does not confine length of request header. Because of that a specially crafted request can allocate memory on the sever until limit is reached.

Пораженные продукты

Apache HTTP Server from 2.4.17 to 2.4.23

Решение

For a 2.4.23 version a patch is supplied. This will be included in the next release.
Security Advisory — Apache Software Foundation

Первичный источник обнаружения
Apache httpd 2.4 vulnerabilities
Оказываемое влияние
?
DoS 
[?]
Связанные продукты
Apache HTTP Server
CVE-IDS
CVE-2016-87405.0Critical