[Secure-testing-team] Bug#847124: apache2: CVE-2016-8740: erver memory can be exhausted and service denied when HTTP/2 is used

Salvatore Bonaccorso carnil at debian.org
Mon Dec 5 20:13:04 UTC 2016


Source: apache2
Version: 2.4.23-8
Severity: important
Tags: security upstream patch

Hi

CVE-2016-8740 was announced for apache, CVE-2016-8740, Server memory
can be exhausted and service denied when HTTP/2 is used.

Post to oss-security at:
http://www.openwall.com/lists/oss-security/2016/12/05/14

Patch: https://svn.apache.org/r1772576

Regards,
Salvatore



More information about the Secure-testing-team mailing list