Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 677000 - www-servers/apache: Multiple vulnerabilities
Summary: www-servers/apache: Multiple vulnerabilities
Status: RESOLVED DUPLICATE of bug 676064
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
Depends on:
Reported: 2019-01-31 18:33 UTC by Dimitris Nakos (sokan)
Modified: 2019-03-20 16:02 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Note You need to log in before you can comment on or make changes to this bug.
Description Dimitris Nakos (sokan) 2019-01-31 18:33:12 UTC
By sending request bodies in a slow loris way to plain resources, the h2 stream for that request unnecessarily occupied a server thread cleaning up that incoming data. This affects only HTTP/2 connections. A possible mitigation is to not enable the h2 protocol. 

In Apache HTTP Server 2.4 release 2.4.37 and prior, mod_session checks the session expiry time before decoding the session. This causes session expiry time to be ignored for mod_session_cookie sessions since the expiry time is loaded when the session is decoded.

A bug exists in the way mod_ssl handled client renegotiations. A remote attacker could send a carefully crafted request that would cause mod_ssl to enter a loop leading to a denial of service. This bug can be only triggered with Apache HTTP Server version 2.4.37 when using OpenSSL version 1.1.1 or later, due to an interaction in changes to handling of renegotiation attempts. 

All issues fixed in Apache httpd 2.4.38 ( 
Please bump when possible.

--Gentoo Security Padawan--
Comment 1 Tomáš Mózes 2019-02-01 04:22:22 UTC

*** This bug has been marked as a duplicate of bug 676064 ***
Comment 2 Tomáš Mózes 2019-02-01 04:24:14 UTC
Already in tree.