Описание
Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests.
This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67.
A flaw was found in HTTP/2, affecting various web servers. A remote attacker can exploit this vulnerability by combining an HPACK compression bomb with a zero-byte flow-control window. This technique allows a small amount of data to expand into large memory allocations on the server, which are then held, leading to a denial of service (DoS) by rendering the server inaccessible.
Отчет
The Apache's httpd HTTP/2 protocol implementation has a denial-of-service (DoS) vulnerability that is rated as Important. An unauthenticated remote attacker can exploit this flaw by combining HPACK compression with flow control manipulation, leading to significant server memory exhaustion and rendering the service inaccessible. This vulnerability exists in default HTTP/2 configurations.
Меры по смягчению последствий
See the security bulletin for a detailed mitigation procedure.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat JBoss Core Services | jbcs-httpd24-apache-commons-daemon | Not affected | ||
| Red Hat JBoss Core Services | jbcs-httpd24-apache-commons-daemon-jsvc | Not affected | ||
| Red Hat JBoss Core Services | jbcs-httpd24-apr | Not affected | ||
| Red Hat JBoss Core Services | jbcs-httpd24-apr-util | Not affected | ||
| Red Hat JBoss Core Services | jbcs-httpd24-brotli | Not affected | ||
| Red Hat JBoss Core Services | jbcs-httpd24-compose | Not affected | ||
| Red Hat JBoss Core Services | jbcs-httpd24-curl | Not affected | ||
| Red Hat JBoss Core Services | jbcs-httpd24-dist | Not affected | ||
| Red Hat JBoss Core Services | jbcs-httpd24-jansson | Not affected | ||
| Red Hat JBoss Core Services | jbcs-httpd24-mod_cluster-native | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67.
Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67.
Memory Allocation with Excessive Size Value vulnerability in Apache HT ...
EPSS
7.5 High
CVSS3