CVE-2018-17189 log
| Source |
|
| Severity | High |
| Remote | Yes |
| Type | Denial of service |
| Description | By sending request bodies in a slow loris way to plain resources, the h2 stream of Apache HTTP Server before 2.4.38 for that request unnecessarily occupied a server thread cleaning up that incoming data. This affects only HTTP/2 connections. A possible mitigation is to not enable the h2 protocol. |
| Group | Package | Affected | Fixed | Severity | Status | Ticket |
|---|---|---|---|---|---|---|
| AVG-857 | apache | 2.4.37-1 | 2.4.38-1 | High | Fixed |
| Date | Advisory | Group | Package | Severity | Type |
|---|---|---|---|---|---|
| 24 Jan 2019 | ASA-201901-14 | AVG-857 | apache | High | multiple issues |
| References |
|---|
https://httpd.apache.org/security/vulnerabilities_24.html#2.4.38 |