FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

Apache httpd -- multiple vulnerabilities

Affected packages
apache24 < 2.4.59
mod_http2 < 2.0.27

Details

VuXML ID 8e6f684b-f333-11ee-a573-84a93843eb75
Discovery 2024-04-04
Entry 2024-04-05

The Apache httpd project reports:

HTTP/2 DoS by memory exhaustion on endless continuation frames

HTTP Response Splitting in multiple modules

References

CVE Name CVE-2024-24795
CVE Name CVE-2024-27316
CVE Name CVE-2024-38709
URL https://downloads.apache.org/httpd/CHANGES_2.4.59