Apache HTTP Server DoS Vulnerability (CVE-2016-1546)
Apache HTTP Server DoS Vulnerability (CVE-2016-1546)
Release date:
Updated on:
Affected Systems:
Apache Group HTTP Server 2.4.18
Apache Group HTTP Server 2.4.17
Description:
CVE (CAN) ID: CVE-2016-1546
Apache HTTP Server is an open-source Web Server of the Apache Software Foundation.
Apache HTTP Server 2.4.17 and 2.4.18, after mod_http2 is enabled, the number of synchronization streams for a single HTTP/2 connection is not limited. By modifying the traffic control window, remote attackers can block Server threads for a long time, this causes a denial of service by mutex wait on the worker thread.
<* Source: Noam Mazor
Link: http://httpd.apache.org/security/vulnerabilities_24.html
*>
Suggestion:
Vendor patch:
Apache Group
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.apache.org/dist/httpd/CHANGES_2.4
Http://svn.apache.org/viewvc? View = revision & revision = 1733727
Http://httpd.apache.org/security/vulnerabilities_24.html
This article permanently updates the link address: