CVE-2016-8740
05.12.2016, 19:59
The mod_http2 module in the Apache HTTP Server 2.4.17 through 2.4.23, when the Protocols configuration includes h2 or h2c, does not restrict request-header length, which allows remote attackers to cause a denial of service (memory consumption) via crafted CONTINUATION frames in an HTTP/2 request.Enginsight
Vendor | Product | Version |
---|---|---|
apache | http_server | 2.4.17 |
apache | http_server | 2.4.18 |
apache | http_server | 2.4.19 |
apache | http_server | 2.4.20 |
apache | http_server | 2.4.21 |
apache | http_server | 2.4.22 |
apache | http_server | 2.4.23 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References