The mod_http2 module in the Apache HTTP Server 2.4.17 through 2.4.23, when the Protocols configuration includes h2 or h2c, does not restrict request-header length, which allows remote attackers to cause a denial of service (memory consumption) via crafted CONTINUATION frames in an HTTP/2 request.
http://packetstormsecurity.com/files/140023/Apache-HTTPD-Web-Server-2.4.23-Memory-Exhaustion.html
http://rhn.redhat.com/errata/RHSA-2017-1415.html
http://www.securityfocus.com/bid/94650
http://www.securitytracker.com/id/1037388
https://access.redhat.com/errata/RHSA-2017:1161
https://access.redhat.com/errata/RHSA-2017:1413
https://access.redhat.com/errata/RHSA-2017:1414
https://github.com/apache/httpd/commit/29c63b786ae028d82405421585e91283c8fa0da3
https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03725en_us
https://lists.apache.org/thread.html/[email protected]%3Ccvs.httpd.apache.org%3E
https://lists.apache.org/thread.html/[email protected]%3Ccvs.httpd.apache.org%3E
https://lists.apache.org/thread.html/[email protected]%3Ccvs.httpd.apache.org%3E
https://lists.apache.org/thread.html/[email protected]%3Ccvs.httpd.apache.org%3E
https://lists.apache.org/thread.html/rf6449464[email protected]%3Ccvs.httpd.apache.org%3E
https://security.gentoo.org/glsa/201701-36
https://security.netapp.com/advisory/ntap-20180423-0001/
https://support.apple.com/HT208221
Source: MITRE
Published: 2016-12-05
Updated: 2021-03-30
Type: CWE-399
Base Score: 5
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P
Impact Score: 2.9
Exploitability Score: 10
Severity: MEDIUM
Base Score: 7.5
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Impact Score: 3.6
Exploitability Score: 3.9
Severity: HIGH
OR
cpe:2.3:a:apache:http_server:2.4.17:*:*:*:*:*:*:*
cpe:2.3:a:apache:http_server:2.4.18:*:*:*:*:*:*:*
cpe:2.3:a:apache:http_server:2.4.19:*:*:*:*:*:*:*
cpe:2.3:a:apache:http_server:2.4.20:*:*:*:*:*:*:*
cpe:2.3:a:apache:http_server:2.4.21:*:*:*:*:*:*:*
ID | Name | Product | Family | Severity |
---|---|---|---|---|
700511 | macOS < 10.13 Multiple Vulnerabilities | Nessus Network Monitor | Operating System Detection | critical |
98910 | Apache 2.4.x < 2.4.25 Multiple Vulnerabilities (httpoxy) | Web Application Scanning | Component Vulnerability | medium |
117316 | RHEL 6 : JBoss Core Services (RHSA-2017:1414) | Nessus | Red Hat Local Security Checks | high |
117315 | RHEL 7 : JBoss Core Services (RHSA-2017:1413) | Nessus | Red Hat Local Security Checks | high |
104379 | macOS and Mac OS X Multiple Vulnerabilities (Security Update 2017-001 and 2017-004) | Nessus | MacOS X Local Security Checks | critical |
103598 | macOS < 10.13 Multiple Vulnerabilities | Nessus | MacOS X Local Security Checks | critical |
101044 | Tenable SecurityCenter Apache 2.4.x < 2.4.25 Multiple Vulnerabilities (TNS-2017-04) (httpoxy) | Nessus | Misc. | high |
99134 | macOS 10.12.x < 10.12.4 Multiple Vulnerabilities (httpoxy) | Nessus | MacOS X Local Security Checks | critical |
97726 | Tenable SecurityCenter 5.x < 5.4.3 Multiple Vulnerabilities (TNS-2017-04) (httpoxy) | Nessus | Misc. | medium |
96863 | openSUSE Security Update : apache2 (openSUSE-2017-154) | Nessus | SuSE Local Security Checks | medium |
9908 | Apache HTTP Server 2.4.x < 2.4.25 Multiple Vulnerabilities | Nessus Network Monitor | Web Servers | medium |
96653 | SUSE SLES12 Security Update : apache2 (SUSE-SU-2017:0203-1) | Nessus | SuSE Local Security Checks | medium |
96516 | GLSA-201701-36 : Apache: Multiple vulnerabilities (httpoxy) | Nessus | Gentoo Local Security Checks | medium |
96451 | Apache 2.4.x < 2.4.25 Multiple Vulnerabilities (httpoxy) | Nessus | Web Servers | medium |
96090 | Slackware 14.0 / 14.1 / 14.2 / current : httpd (SSA:2016-358-01) (httpoxy) | Nessus | Slackware Local Security Checks | medium |
96037 | FreeBSD : Apache httpd -- several vulnerabilities (862d6ab3-c75e-11e6-9f98-20cf30e32f6d) (httpoxy) | Nessus | FreeBSD Local Security Checks | medium |
95683 | Fedora 24 : httpd (2016-b39fedec11) | Nessus | Fedora Local Security Checks | medium |
95655 | Fedora 25 : httpd (2016-260d22944d) | Nessus | Fedora Local Security Checks | medium |
95586 | FreeBSD : Apache httpd -- denial of service in HTTP/2 (cb0bf1ec-bb92-11e6-a9a5-b499baebfeaf) | Nessus | FreeBSD Local Security Checks | medium |