Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-27316

Опубликовано: 04 апр. 2024
Источник: ubuntu
Приоритет: medium
EPSS Критический
CVSS3: 7.5

Описание

HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory exhaustion.

РелизСтатусПримечание
devel

released

2.4.58-1ubuntu8.1
esm-infra-legacy/trusty

not-affected

code not present, HTTP/2 via mod_http2 introduced in 2.4.17; trusty ships 2.4.7
esm-infra-legacy/xenial

released

2.4.18-2ubuntu3.17+esm12
esm-infra/bionic

released

2.4.29-1ubuntu4.27+esm2
esm-infra/focal

released

2.4.41-4ubuntu3.17
esm-infra/xenial

released

2.4.18-2ubuntu3.17+esm12
focal

released

2.4.41-4ubuntu3.17
jammy

released

2.4.52-1ubuntu4.9
mantic

released

2.4.57-2ubuntu2.4
noble

released

2.4.58-1ubuntu8.1

Показывать по

EPSS

Процентиль: 100%
0.91327
Критический

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
больше 2 лет назад

HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory exhaustion.

CVSS3: 7.5
nvd
больше 2 лет назад

HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory exhaustion.

CVSS3: 7.5
msrc
6 месяцев назад

Apache HTTP Server: HTTP/2 DoS by memory exhaustion on endless continuation frames

CVSS3: 7.5
debian
больше 2 лет назад

HTTP/2 incoming headers exceeding the limit are temporarily buffered i ...

rocky
около 2 лет назад

Moderate: mod_http2 security update

EPSS

Процентиль: 100%
0.91327
Критический

7.5 High

CVSS3