Lucene search

K
freebsdFreeBSDF923205F-6E66-11EE-85EB-84A93843EB75
HistoryOct 19, 2023 - 12:00 a.m.

Apache httpd -- Multiple vulnerabilities

2023-10-1900:00:00
vuxml.freebsd.org
27
apache
http server
multiple vulnerabilities
http/2 stream
mod_macro buffer over-read
memory not reclaimed
dos
initial windows size
unix

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.01 Low

EPSS

Percentile

83.8%

The Apache httpd project reports:

CVE-2023-45802: Apache HTTP Server: HTTP/2 stream
memory not reclaimed right away on RST
CVE-2023-43622: Apache HTTP Server: DoS in HTTP/2 with
initial windows size 0
CVE-2023-31122: mod_macro buffer over-read

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchapache24< 2.4.58UNKNOWN

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.01 Low

EPSS

Percentile

83.8%