Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-11763

Опубликовано: 25 сент. 2018
Источник: redhat
CVSS3: 7.5
EPSS Средний

Описание

In Apache HTTP Server 2.4.17 to 2.4.34, by sending continuous, large SETTINGS frames a client can occupy a connection, server thread and CPU time without any connection timeout coming to effect. This affects only HTTP/2 connections. A possible mitigation is to not enable the h2 protocol.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6httpdNot affected
Red Hat Enterprise Linux 7httpdNot affected
Red Hat Enterprise Linux 8httpdNot affected
Red Hat Enterprise Linux 8mod_http2Not affected
Red Hat JBoss Enterprise Application Platform 5httpdNot affected
Red Hat JBoss Enterprise Application Platform 6httpdNot affected
Red Hat JBoss Enterprise Web Server 2httpdNot affected
Red Hat JBoss Web Server 3httpdNot affected
Red Hat Mobile Application Platform 4httpdWill not fix
Red Hat Virtualization 4httpdNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1633399httpd: DoS for HTTP/2 connections by continuous SETTINGS frames

EPSS

Процентиль: 95%
0.17401
Средний

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 7 лет назад

In Apache HTTP Server 2.4.17 to 2.4.34, by sending continuous, large SETTINGS frames a client can occupy a connection, server thread and CPU time without any connection timeout coming to effect. This affects only HTTP/2 connections. A possible mitigation is to not enable the h2 protocol.

CVSS3: 5.9
nvd
больше 7 лет назад

In Apache HTTP Server 2.4.17 to 2.4.34, by sending continuous, large SETTINGS frames a client can occupy a connection, server thread and CPU time without any connection timeout coming to effect. This affects only HTTP/2 connections. A possible mitigation is to not enable the h2 protocol.

CVSS3: 5.9
debian
больше 7 лет назад

In Apache HTTP Server 2.4.17 to 2.4.34, by sending continuous, large S ...

suse-cvrf
около 7 лет назад

Security update for apache2

suse-cvrf
больше 7 лет назад

Security update for apache2

EPSS

Процентиль: 95%
0.17401
Средний

7.5 High

CVSS3

Уязвимость CVE-2018-11763