Summary: | <www-servers/apache-2.4.20: mod_http2 denial-of-service by thread starvation (CVE-2016-1546) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Agostino Sarubbo <ago> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | minor | CC: | polynomial-c |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://bugzilla.redhat.com/show_bug.cgi?id=1336350 | ||
See Also: | https://bugs.gentoo.org/show_bug.cgi?id=468302 | ||
Whiteboard: | B3 [glsa cve] | ||
Package list: | Runtime testing required: | --- | |
Bug Depends on: | 588138 | ||
Bug Blocks: |
Description
Agostino Sarubbo
![]() Arches please test and mark stable the following list of packages: =app-admin/apache-tools-2.4.20 =www-servers/apache-2.4.20 Target KEYWORDS are: alpha amd64 arm ~arm64 hppa ia64 ~mips ppc ppc64 ~s390 ~sh sparc x86 ~amd64-fbsd ~sparc-fbsd ~x86-fbsd ~x86-freebsd ~amd64-linux ~x86-linux ~ppc-macos ~x64-macos ~x86-macos ~m68k-mint ~sparc64-solaris ~x64-solaris amd64 stable x86 stable arm stable Stable for HPPA PPC64. Stable on alpha. ppc stable Stabilization of higher version happening in bug 588138 CVE-2016-1546 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-1546): The Apache HTTP Server 2.4.17 and 2.4.18, when mod_http2 is enabled, does not limit the number of simultaneous stream workers for a single HTTP/2 connection, which allows remote attackers to cause a denial of service (stream-processing outage) via modified flow-control windows. Added to existing GLSA. This issue was resolved and addressed in GLSA 201610-02 at https://security.gentoo.org/glsa/201610-02 by GLSA coordinator Kristian Fiskerstrand (K_F). |