When under stress, closing many connections, the HTTP/2 handling code in Apache httpd 2.4.26 would sometimes access memory after it has been freed, resulting in potentially erratic behaviour.
CVSS Details
- CVSS 3.0 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade apache2 | Oct 1, 2024 | Jul 13, 2017 |
| Apache Httpd | — | Upgrade to the latest version of Apache HTTPD | Jul 14, 2017 | Jul 13, 2017 |
| Apple Osx Apache | — | Apply OS X security update 2017-001 SierraApply OS X security update 2017-004 El Capitan | Nov 1, 2017 | Jul 13, 2017 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jul 13, 2017 |
| Freebsd | — | Upgrade apache24 | Jul 14, 2017 | Jul 13, 2017 |
| Gentoo Linux | — | Upgrade www-servers/apache. | Oct 30, 2017 | Jul 13, 2017 |
| Hpux | — | Update hpuxwsAPACHE to the latest version | Mar 28, 2022 | Jul 13, 2017 |
| Ibm Http_server | — | Apply IBM HTTP Server version 9.0.0.5 or later | Jun 22, 2018 | Jul 13, 2017 |
| Oracle Solaris | — | Upgrade web/server/apache-24/module/apache-ldap to version 2.4.27-0.175.3.24.0.1.0 on Solaris 11.3Upgrade web/server/apache-24/module/apache-dbd to version 2.4.27-0.175.3.24.0.1.0 on Solaris 11.3Upgrade web/server/apache-24/module/apache-ssl-fips-140 to version 2.4.27-0.175.3.24.0.1.0 on Solaris 11.3Upgrade web/server/apache-24/module/apache-lua to version 2.4.27-0.175.3.24.0.1.0 on Solaris 11.3Upgrade web/server/apache-24 to version 2.4.27-0.175.3.24.0.1.0 on Solaris 11.3Upgrade web/server/apache-24/module/apache-ssl to version 2.4.27-0.175.3.24.0.1.0 on Solaris 11.3 | Sep 19, 2017 | Jul 13, 2017 |
| Suse | — | Upgrade apache2-example-pagesUpgrade apache2-docUpgrade apache2-workerUpgrade apache2Upgrade apache2-preforkUpgrade apache2-develUpgrade apache2-utils | Jan 30, 2018 | Jul 13, 2017 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jul 13, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub