Apache.httpd.mod_http2.h2_session_process.DoS
Description
This indicates an attack attempt to exploit a Denial of Service Vulnerability in Apache Software Foundation HTTP Server.
The vulnerability is due to improper validation of HTTP/2 requests with an initial window size of zero. A remote, unauthenticated attacker could exploit this vulnerability by sending crafted requests to the target server. Successful exploitation could result in denial of service conditions on the target server.
Affected Products
Apache Software Foundation HTTP Server 2.4.55 through 2.4.57
Impact
Denial of Service: Remote attackers can crash vulnerable systems.
Recommended Actions
Apply the most recent upgrade or patch from the vendor.
https://seclists.org/oss-sec/2023/q4/150
Coverage
| IPS (Regular DB) | |
| IPS (Extended DB) |