Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:17956
HistoryMay 02, 2019 - 6:10 a.m.

Denial Of Service (DoS)

2019-05-0206:10:16
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8

0.027 Low

EPSS

Percentile

90.5%

Apache HTTP Server is vulnerable to denial of service(DoS) attacks. This occurs in httpd’s handling of the LimitRequestFields directive in mod_http2, affecting servers with HTTP/2 enabled. An attacker could send crafted CONTINUATION frames in an HTTP/2 requests with headers larger than the server’s available memory which leads the application to crash.

References