Resource management error in Apache HTTP Server - CVE-2018-11763
Published: September 27, 2018
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to incorrect handling of large SETTINGS frames in HTTP/2 connections. A remote attacker can repeatedly send large SETTINGS frames within an established HTTP/2 connection and consume all available threads and CPU time.
Successful exploitation of the vulnerability may allow an attacker to perform a denial of service (DoS) attack.
Affected software
Amazon Linux AMI
Opensuse
Fedora
Tenable.sc
apache2 (Alpine package)
mod_http2
Dell Secure Connect Gateway
Oracle Secure Global Desktop
How to mitigate CVE-2018-11763
Tenable.sc - update to 5.13.0
apache2 (Alpine package) - update to 2.4.35-r0
Dell Secure Connect Gateway - update to 5.12.00.10
mod_http2 - addressed in versions 1.11.1-1.fc27, 1.11.1-1.fc28, 1.11.1-1.fc29
External References
Related Security Bulletins
- Remote denial of service in Apache HTTP Server
- OpenSUSE Linux update for apache2
- OpenSUSE Linux update for apache2
- Amazon Linux AMI update for httpd24
- Multiple vulnerabilities in Tenable.sc
- Resource management error in apache2 (Alpine package)
- Multiple vulnerabilities in DELL Secure Connect Gateway Security
- Fedora 29 update for mod_http2
- Fedora 27 update for mod_http2
- Fedora 28 update for mod_http2
- Multiple vulnerabilities in Oracle Secure Global Desktop