Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2024-8680

Опубликовано: 30 окт. 2024
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2024-8680: mod_http2 security update (LOW)

[2.0.26-2.1]

  • Resolves: RHEL-45803 - mod_http2: DoS by null pointer in websocket over HTTP/2 (CVE-2024-36387)

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

mod_http2

2.0.26-2.el9_4.1

Oracle Linux x86_64

mod_http2

2.0.26-2.el9_4.1

Связанные CVE

Связанные уязвимости

CVSS3: 5.4
ubuntu
12 месяцев назад

Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a crash of the server process, degrading performance.

CVSS3: 3.7
redhat
12 месяцев назад

Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a crash of the server process, degrading performance.

CVSS3: 5.4
nvd
12 месяцев назад

Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a crash of the server process, degrading performance.

CVSS3: 5.4
msrc
7 месяцев назад

Описание отсутствует

CVSS3: 5.4
debian
12 месяцев назад

Serving WebSocket protocol upgrades over a HTTP/2 connection could res ...