CVE-2018-17189 log
Source |
|
Severity | High |
Remote | Yes |
Type | Denial of service |
Description | By sending request bodies in a slow loris way to plain resources, the h2 stream of Apache HTTP Server before 2.4.38 for that request unnecessarily occupied a server thread cleaning up that incoming data. This affects only HTTP/2 connections. A possible mitigation is to not enable the h2 protocol. |
Group | Package | Affected | Fixed | Severity | Status | Ticket |
---|---|---|---|---|---|---|
AVG-857 | apache | 2.4.37-1 | 2.4.38-1 | High | Fixed |
Date | Advisory | Group | Package | Severity | Type |
---|---|---|---|---|---|
24 Jan 2019 | ASA-201901-14 | AVG-857 | apache | High | multiple issues |
References |
---|
https://httpd.apache.org/security/vulnerabilities_24.html#2.4.38 |