In lavorazione appositamente HTTP / 2 richieste, i lavoratori sarebbero stati assegnati 60 secondi più del necessario, portando ad esaurimento dei lavoratori e una negazione del servizio. Risolto in Apache HTTP Server 2.4.34 (interessato 2.4.18-2.4.30,2.4.33). |
https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2018-1333 https://security.netapp.com/advisory/ntap-20180926-0007/ https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03909en_us https://www.tenable.com/security/tns-2019-09 https://lists.apache.org/thread.html/[email protected]%3Ccvs.httpd.apache.org%3E https://lists.apache.org/thread.html/[email protected]%3Ccvs.httpd.apache.org%3E https://lists.apache.org/thread.html/[email protected]%3Ccvs.httpd.apache.org%3E https://lists.apache.org/thread.html/[email protected]%3Ccvs.httpd.apache.org%3E https://access.redhat.com/errata/RHSA-2018:3558 https://access.redhat.com/errata/RHSA-2019:0366 https://access.redhat.com/errata/RHSA-2019:0367 http://www.securitytracker.com/id/1041402 https://usn.ubuntu.com/3783-1/ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1333 |
Vulnerabilità: CVE-2018-1333
