PT-2018-1588 · Apache+3 · Apache Http Server+3
Gal Goldshtein
·
Published
2018-09-25
·
Updated
2024-06-15
·
CVE-2018-11763
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Apache HTTP Server versions 2.4.17 through 2.4.34
Description
The issue is related to insufficient input validation in the Apache HTTP Server, which can be exploited by a remote attacker to cause a denial of service by exhausting the limit of simultaneously open connections through continuous sending of maximum-sized SETTINGS frames. This affects only HTTP/2 connections.
Recommendations
For Apache HTTP Server versions 2.4.17 through 2.4.34, a possible mitigation is to not enable the h2 protocol.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Apache Http Server
Suse
Ubuntu