The Apache HTTP Server 2.4.17 and 2.4.18, when mod_http2 is enabled, does not limit the number of simultaneous stream workers for a single HTTP/2 connection, which allows remote attackers to cause a denial of service (stream-processing outage) via modified flow-control windows.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: certcc
Published: 2016-07-06T14:00:00
Updated: 2024-08-05T23:02:11.567Z
Reserved: 2016-01-07T00:00:00
Link: CVE-2016-1546
Vulnrichment
No data.
NVD
Status : Modified
Published: 2016-07-06T14:59:01.503
Modified: 2024-11-21T02:46:36.997
Link: CVE-2016-1546
Redhat