The mod_http2 module in the Apache HTTP Server 2.4.17 through 2.4.23, when the Protocols configuration includes h2 or h2c, does not restrict request-header length, which allows remote attackers to cause a denial of service (memory consumption) via crafted CONTINUATION frames in an HTTP/2 request.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade apache2 | Aug 30, 2017 | Jul 27, 2017 |
| Apache Httpd | — | Upgrade to the latest version of Apache HTTPD | Dec 5, 2016 | Dec 5, 2016 |
| Apple Osx Apache | — | Upgrade macOS to the latest versionApply OS X security update 2017-001 SierraApply OS X security update 2017-004 El Capitan | Mar 28, 2017 | Dec 5, 2016 |
| Debian | — | Upgrade apache2 | Jul 30, 2024 | Dec 5, 2016 |
| Freebsd | — | Upgrade mod_http2-develUpgrade apache24 | Dec 21, 2016 | Dec 21, 2016 |
| Gentoo Linux | — | Upgrade www-servers/apache. | Oct 30, 2017 | Dec 5, 2016 |
| Hpux | — | Update hpuxws24APACHE.MOD_PERL to the latest versionUpdate hpuxws24APACHE.MOD_PERL2 to the latest versionUpdate hpuxws24APACHE.AUTH_LDAP2 to the latest versionUpdate hpuxws24APACHE.WEBPROXY2 to the latest versionUpdate hpuxws24APACHE.MOD_JK2 to the latest versionUpdate hpuxws24APACHE.AUTH_LDAP to the latest versionUpdate hpuxws24APACHE.WEBPROXY to the latest versionUpdate hpuxws24APACHE.APACHE to the latest versionUpdate hpuxws24APACHE.APACHE2 to the latest versionUpdate hpuxws24APACHE.MOD_JK to the latest version | Aug 11, 2017 | Dec 5, 2016 |
| Ibm Http_server | — | Apply IBM HTTP Server version 9.0.0.3 or later | Jun 22, 2018 | Dec 5, 2016 |
| Oracle Solaris | — | Upgrade web/server/apache-24/module/apache-gss to version 2.4.25-0.175.3.17.0.3.0 on Solaris 11.3Upgrade web/server/apache-24/module/apache-ssl to version 2.4.25-0.175.3.17.0.3.0 on Solaris 11.3Upgrade web/server/apache-24/module/apache-dbd to version 2.4.25-0.175.3.17.0.3.0 on Solaris 11.3Upgrade web/server/apache-24/module/apache-lua to version 2.4.25-0.175.3.17.0.3.0 on Solaris 11.3Upgrade web/server/apache-24/module/apache-ssl-fips-140 to version 2.4.25-0.175.3.17.0.3.0 on Solaris 11.3Upgrade web/server/apache-24 to version 2.4.25-0.175.3.17.0.3.0 on Solaris 11.3Upgrade web/server/apache-24/module/apache-ldap to version 2.4.25-0.175.3.17.0.3.0 on Solaris 11.3 | May 29, 2017 | Dec 5, 2016 |
| Suse | — | Upgrade apache2-preforkUpgrade apache2-example-pagesUpgrade apache2-develUpgrade apache2-docUpgrade apache2-utilsUpgrade apache2-workerUpgrade apache2Upgrade apache2-event | Jan 20, 2017 | Dec 5, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub