[ALAS2-2024-2524] Amazon Linux 2 2017.12 - ALAS2-2024-2524: important priority package update for mod_http2

Severity Important
Affected Packages 6
CVEs 1

Package updates are available for Amazon Linux 2 that fix the following vulnerabilities:
CVE-2024-27316:
HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory exhaustion.

Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/amazonlinux/mod_http2?arch=x86_64&distro=amazonlinux-2 amazonlinux mod_http2 < 1.15.19-1.amzn2.0.2 amazonlinux-2 x86_64
Affected pkg:rpm/amazonlinux/mod_http2?arch=i686&distro=amazonlinux-2 amazonlinux mod_http2 < 1.15.19-1.amzn2.0.2 amazonlinux-2 i686
Affected pkg:rpm/amazonlinux/mod_http2?arch=aarch64&distro=amazonlinux-2 amazonlinux mod_http2 < 1.15.19-1.amzn2.0.2 amazonlinux-2 aarch64
Affected pkg:rpm/amazonlinux/mod_http2-debuginfo?arch=x86_64&distro=amazonlinux-2 amazonlinux mod_http2-debuginfo < 1.15.19-1.amzn2.0.2 amazonlinux-2 x86_64
Affected pkg:rpm/amazonlinux/mod_http2-debuginfo?arch=i686&distro=amazonlinux-2 amazonlinux mod_http2-debuginfo < 1.15.19-1.amzn2.0.2 amazonlinux-2 i686
Affected pkg:rpm/amazonlinux/mod_http2-debuginfo?arch=aarch64&distro=amazonlinux-2 amazonlinux mod_http2-debuginfo < 1.15.19-1.amzn2.0.2 amazonlinux-2 aarch64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...