CVE-2020-11993: Push Diary Crash on Specifically Crafted HTTP/2 Header
Severity: moderate Vendor: Apache Software Foundation Versions Affected: Apache HTTP Server 2.4.20 to 2.4.43 Description: Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logging statements were made on the wrong connection, causing concurrent use of memory pools. Configuring the LogLevel of mod_http2 above "info" will mitigate this vulnerability for unpatched servers. Mitigation: Credit: Felix Wilhelm of Google Project Zero References: https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2020-11993