Дата обнаружения
|
05/12/2016 |
Уровень угрозы
|
Warning |
Описание
|
An unspecified vulnerability was found in Apache HTTP Server 2.4.17 through 2.4.23. By exploiting this vulnerability malicious users can cause denial of service. This vulnerability can be exploited remotely via crafted continuation frames in a HTTP/2 request. Technical details Vulnerability occurs in mod_http2 module, when the Protocols configuration (including h2/h2c) does not confine length of request header. Because of that a specially crafted request can allocate memory on the sever until limit is reached. |
Пораженные продукты
|
Apache HTTP Server from 2.4.17 to 2.4.23 |
Решение
|
For a 2.4.23 version a patch is supplied. This will be included in the next release. |
Первичный источник обнаружения
|
Apache httpd 2.4 vulnerabilities |
Оказываемое влияние
?
|
DoS
[?]
|
Связанные продукты
|
Apache HTTP Server |
CVE-IDS
|
|
Эксплуатация
|
The following public exploits exists for this vulnerability: |
Узнай статистику распространения уязвимостей в твоем регионе |