versions Apache HTTP Server 2.4.20 à 2.4.43. Une valeur spécialement conçue pour l’en-tête « Cache-Digest » dans une requête HTTP / 2 entraînerait un plantage lorsque le serveur tente en fait de HTTP / 2 PUSH une ressource par la suite. Configuration de la fonction HTTP / 2 via « H2Push off » atténuera cette vulnérabilité pour les serveurs non patchés.
https://security.netapp.com/advisory/ntap-20200814-0005/
https://security.netapp.com/advisory/ntap-20200814-0005/
https://www.debian.org/security/2020/dsa-4757
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4NKWG2EXAQQB6LMLATKZ7KLSRGCSHVAN/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ITVFDBVM6E3JF3O7RYLRPRCH3RDRHJJY/
https://security.gentoo.org/glsa/202008-04
http://packetstormsecurity.com/files/160392/Apache-2.4.43-mod_http2-Memory-Corruption.html
https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2020-9490
https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2020-9490
https://www.oracle.com/security-alerts/cpuoct2020.html
https://www.oracle.com/security-alerts/cpuoct2020.html
https://lists.apache.org/thread.html/r9e9f1a7609760f0f80562eaaec2aa3c32d525c3e0fca98b475240c71@%3Cdev.httpd.apache.org%3E
https://lists.apache.org/thread.html/r623de9b2b2433a87f3f3a15900419fc9c00c77b26936dfea4060f672@%3Cdev.httpd.apache.org%3E
https://lists.apache.org/thread.html/r5debe8f82728a00a4a68bc904dd6c35423bdfc8d601cfb4579f38bf1@%3Cdev.httpd.apache.org%3E
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00068.html
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00071.html
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00081.html
https://usn.ubuntu.com/4458-1/
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9490