Bug#904106: apache2: CVE-2018-1333: DoS for HTTP/2 connections by crafted requests

2018-07-19 Thread Salvatore Bonaccorso
Source: apache2 Version: 2.4.18-1 Severity: important Tags: security upstream Hi, The following vulnerability was published for apache2. CVE-2018-1333[0]: | By specially crafting HTTP/2 requests, workers would be allocated 60 | seconds longer than necessary, leading to worker exhaustion and a |

Bug#904107: apache2: CVE-2018-8011: mod_md, DoS via Coredumps on specially crafted requests

2018-07-19 Thread Salvatore Bonaccorso
Source: apache2 Version: 2.4.33-1 Severity: important Tags: security upstream Hi, The following vulnerability was published for apache2. CVE-2018-8011[0]: | By specially crafting HTTP requests, the mod_md challenge handler | would dereference a NULL pointer and cause the child process to | segfa