All errata/c10f1/ALT-PU-2024-9963-3
ALT-PU-2024-9963-3

Package update apache2-mod_http2 in branch c10f1

Version2.0.29-alt1
Published2024-07-22
Max severityMEDIUM
Severity:

Closed issues (2)

BDU:2024-05194
MEDIUM5.9

Уязвимость протокола WebSocket веб-сервера Apache HTTP Server, позволяющая нарушителю вызвать отказ в обслуживании

Published: 2024-07-12Modified: 2025-01-31
CVSS 3.xMEDIUM 5.9
CVSS:3.x/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.0MEDIUM 5.4
CVSS:2.0/AV:N/AC:H/Au:N/C:N/I:N/A:C
References
CVE-2024-36387
MEDIUM5.4

Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a crash of the server process, degrading performance.

Published: 2024-07-01Modified: 2025-11-06
CVSS 3.xMEDIUM 5.4
CVSS:3.x/CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L