First published: Mon May 16 2016(Updated: )
The Apache HTTP Server 2.4.17 and 2.4.18, when mod_http2 is enabled, does not limit the number of simultaneous stream workers for a single HTTP/2 connection, which allows remote attackers to cause a denial of service (stream-processing outage) via modified flow-control windows.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache HTTP server | =2.4.17 | |
Apache HTTP server | =2.4.18 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.