CVE-2018-11763
25.09.2018, 21:29
In Apache HTTP Server 2.4.17 to 2.4.34, by sending continuous, large SETTINGS frames a client can occupy a connection, server thread and CPU time without any connection timeout coming to effect. This affects only HTTP/2 connections. A possible mitigation is to not enable the h2 protocol.Enginsight
Vendor | Product | Version |
---|---|---|
apache | http_server | 2.4.17 ≤ 𝑥 ≤ 2.4.34 |
canonical | ubuntu_linux | 18.04 |
redhat | enterprise_linux | 6.0 |
redhat | enterprise_linux | 7.0 |
redhat | enterprise_linux | 7.4 |
redhat | enterprise_linux | 7.5 |
redhat | enterprise_linux | 7.6 |
oracle | enterprise_manager_ops_center | 12.3.3 |
oracle | hospitality_guest_access | 4.2.0 |
oracle | hospitality_guest_access | 4.2.1 |
oracle | instantis_enterprisetrack | 17.1 |
oracle | instantis_enterprisetrack | 17.2 |
oracle | instantis_enterprisetrack | 17.3 |
oracle | retail_xstore_point_of_service | 7.0 |
oracle | retail_xstore_point_of_service | 7.1 |
oracle | secure_global_desktop | 5.4 |
netapp | storage_automation_store | - |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References