Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67.
| Vendor | Product | Versions |
|---|---|---|
| apache | http_server | 2.4.17 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| apache | http | cert_advisory | 90% |
| debian | debian_linux | cve_cpe | 95% |
| f5 | nginx | cve_cpe | 95% |
| oracle | solaris | cert_advisory | 90% |
Updated description with details on the HTTP/2 Bomb exploit, changed vendor and product to Citrix NetScaler, added affected versions, updated severity to HIGH, and included CVSS score of 8.8.
Updated affected versions to include 2.4.68, changed severity to HIGH, and provided the fixed version number.
Updated severity to MEDIUM, marked exploit as available, and noted that it is actively exploited.
Initial creation