CVE-2023-43622
Summary
| CVE | CVE-2023-43622 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-10-23 07:15:00 UTC |
| Updated | 2023-11-01 18:11:00 UTC |
| Description | An attacker, opening a HTTP/2 connection with an initial window size of 0, was able to block handling of that connection indefinitely in Apache HTTP Server. This could be used to exhaust worker resources in the server, similar to the well known "slow loris" attack pattern.
This has been fixed in version 2.4.58, so that such connection are terminated properly after the configured connection timeout.
This issue affects Apache HTTP Server: from 2.4.55 through 2.4.57.
Users are recommended to upgrade to version 2.4.58, which fixes the issue. |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|
| Application |
Apache |
Http Server |
All |
All |
All |
All |
References
| Reference | Source | Link | Tags |
|---|
| Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project |
MISC |
httpd.apache.org |
|
| October 2023 Apache HTTP Server Vulnerabilities in NetApp Products | NetApp Product Security |
MISC |
security.netapp.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 150737 Apache HTTP Server Prior to 2.4.58 Multiple Security Vulnerabilities
- 199940 Ubuntu Security Notification for Apache Hypertext Transfer Protocol (HTTP) Server Vulnerabilities (USN-6506-1)
- 296106 Oracle Solaris 11.4 Support Repository Update (SRU) 64.157.2 Missing (CPUOCT2023)
- 356549 Amazon Linux Security Advisory for httpd24 : ALAS-2023-1877
- 356605 Amazon Linux Security Advisory for httpd : ALAS2-2023-2322
- 356896 Amazon Linux Security Advisory for httpd : ALAS2023-2023-433
- 503432 Alpine Linux Security Update for apache2
- 505847 Alpine Linux Security Update for apache2
- 691333 Free Berkeley Software Distribution (FreeBSD) Security Update for apache httpd (f923205f-6e66-11ee-85eb-84a93843eb75)
- 907601 Common Base Linux Mariner (CBL-Mariner) Security Update for httpd (31610-1)