vendor:
HTTP Server
by:
Anonymous
7,5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: HTTP Server
Affected Version From: 2.4.17
Affected Version To: 2.4.23
Patch Exists: YES
Related CWE: CVE-2016-8740
CPE: 2.4:a:apache:http_server:2.4.17
Metasploit:
https://www.rapid7.com/db/vulnerabilities/alpine-linux-cve-2016-8740/, https://www.rapid7.com/db/vulnerabilities/hpux-cve-2016-8740/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2016-8740/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2016-8740/, https://www.rapid7.com/db/vulnerabilities/oracle-solaris-cve-2016-8740/, https://www.rapid7.com/db/vulnerabilities/ibm-http_server-cve-2016-8740/, https://www.rapid7.com/db/vulnerabilities/freebsd-cve-2016-8740/, https://www.rapid7.com/db/vulnerabilities/apache-httpd-cve-2016-8740/, https://www.rapid7.com/db/vulnerabilities/apple-osx-apache-cve-2016-8740/
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2016
Apache HTTP Server 2.4.17 through 2.4.23 Denial of Service Vulnerability
The mod_http2 module in the Apache HTTP Server 2.4.17 through 2.4.23, when the Protocols configuration includes h2 or h2c, does not restrict request-header length, which allows remote attackers to cause a denial of service (memory consumption) via crafted CONTINUATION frames in an HTTP/2 request.
Mitigation:
Upgrade to Apache HTTP Server 2.4.24 or later.