Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-1546

Опубликовано: 06 июл. 2016
Источник: debian

Описание

The Apache HTTP Server 2.4.17 and 2.4.18, when mod_http2 is enabled, does not limit the number of simultaneous stream workers for a single HTTP/2 connection, which allows remote attackers to cause a denial of service (stream-processing outage) via modified flow-control windows.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
apache2fixed2.4.20-1package
apache2not-affectedjessiepackage
apache2not-affectedwheezypackage

Примечания

  • HTTP/2 support introduced in 2.4.17

  • Upstream commit: http://svn.apache.org/viewvc?view=revision&revision=1733727

  • Upsteam backport for 2.4.x: http://svn.apache.org/viewvc?view=revision&revision=1734413

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 9 лет назад

The Apache HTTP Server 2.4.17 and 2.4.18, when mod_http2 is enabled, does not limit the number of simultaneous stream workers for a single HTTP/2 connection, which allows remote attackers to cause a denial of service (stream-processing outage) via modified flow-control windows.

redhat
почти 10 лет назад

The Apache HTTP Server 2.4.17 and 2.4.18, when mod_http2 is enabled, does not limit the number of simultaneous stream workers for a single HTTP/2 connection, which allows remote attackers to cause a denial of service (stream-processing outage) via modified flow-control windows.

CVSS3: 5.9
nvd
больше 9 лет назад

The Apache HTTP Server 2.4.17 and 2.4.18, when mod_http2 is enabled, does not limit the number of simultaneous stream workers for a single HTTP/2 connection, which allows remote attackers to cause a denial of service (stream-processing outage) via modified flow-control windows.

CVSS3: 5.9
github
больше 3 лет назад

The Apache HTTP Server 2.4.17 and 2.4.18, when mod_http2 is enabled, does not limit the number of simultaneous stream workers for a single HTTP/2 connection, which allows remote attackers to cause a denial of service (stream-processing outage) via modified flow-control windows.

fstec
больше 9 лет назад

Уязвимость веб-сервера Apache HTTP Server, позволяющая нарушителю вызвать отказ в обслуживании