VDB

DEBIAN-CVE-2018-11763

DEBIAN-CVE-2018-11763 PUBLISHED CVSS 5.900000095367432 MEDIUM

In Apache HTTP Server 2.4.17 to 2.4.34, by sending continuous, large SETTINGS frames a client can occupy a connection, server thread and CPU time without any connection timeout coming to effect. This affects only HTTP/2 connections. A possible mitigation is to not enable the h2 protocol.

Risk Scores

CVSS 3.0
5.900000095367432
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Debian:11apache20, 0, 0
Debian:14apache20, 0, 0
Debian:12apache20, 0, 0
Debian:13apache20, 0, 0

Timeline

  • Sep 25, 2018 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›