Bastien Roucariès pushed to branch master at Debian Security Tracker / security-tracker
Commits: 59151ea3 by Bastien Roucariès at 2024-04-24T15:15:42+00:00 CVE-2024-27316/apache2 Fixed by: https://github.com/apache/httpd/commit/0d73970ec161300a55b630f71bbf72b5c41f28b9 from SVN (https://svn.apache.org/viewvc?view=revision&revision=1916779) SECURITY: CVE-2024-27316: Apache HTTP Server: HTTP/2 DoS by memory exhaustion on endless continuation frames (cve.mitre.org) HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory exhaustion. Credits: Bartek Nowotarski (https://nowotarski.info/) Submitted By: icing - - - - - 1 changed file: - data/CVE/list Changes: ===================================== data/CVE/list ===================================== @@ -6022,6 +6022,7 @@ CVE-2024-27316 (HTTP/2 incoming headers exceeding the limit are temporarily buff NOTE: https://www.kb.cert.org/vuls/id/421644 NOTE: https://www.openwall.com/lists/oss-security/2024/04/04/4 NOTE: https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2024-27316 + NOTE: https://github.com/apache/httpd/commit/0d73970ec161300a55b630f71bbf72b5c41f28b9 CVE-2024-3296 (A timing-based side-channel flaw exists in the rust-openssl package, w ...) - rust-openssl <unfixed> (bug #1068418) [bookworm] - rust-openssl <no-dsa> (Minor issue) View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/59151ea3a3ae40d2105d7d0f485b32df16052ae7 -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/59151ea3a3ae40d2105d7d0f485b32df16052ae7 You're receiving this email because of your account on salsa.debian.org.
_______________________________________________ debian-security-tracker-commits mailing list [email protected] https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits
