Candidate: CVE-2016-8740 PublicDate: 2016-12-05 19:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8740 http://www.openwall.com/lists/oss-security/2016/12/05/14 Description: The mod_http2 module in the Apache HTTP Server 2.4.17 through 2.4.23, when the Protocols configuration includes h2 or h2c, does not restrict request-header length, which allows remote attackers to cause a denial of service (memory consumption) via crafted CONTINUATION frames in an HTTP/2 request. Ubuntu-Description: Notes: mdeslaur> mod_http2 is not built in Ubuntu because it is considered mdeslaur> experimental. Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=847124 https://bugzilla.redhat.com/show_bug.cgi?id=1401528 Priority: medium Discovered-by: Naveen Tiwari Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_apache2: upstream: https://github.com/apache/httpd/commit/29c63b786ae028d82405421585e91283c8fa0da3 upstream: https://svn.apache.org/viewvc?view=revision&revision=1772579 (2.4) upstream_apache2: released (2.4.25-1) precise_apache2: not-affected (code not present) trusty_apache2: not-affected (code not present) trusty/esm_apache2: not-affected (code not present) vivid/stable-phone-overlay_apache2: DNE vivid/ubuntu-core_apache2: DNE xenial_apache2: not-affected (no mod_http2 support) esm-infra/xenial_apache2: not-affected (no mod_http2 support) yakkety_apache2: not-affected (no mod_http2 support) zesty_apache2: not-affected (2.4.25-3ubuntu2) devel_apache2: not-affected (2.4.25-3ubuntu2)