Vulnerability Description
When under stress, closing many connections, the HTTP/2 handling code in Apache httpd 2.4.26 would sometimes access memory after it has been freed, resulting in potentially erratic behaviour.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Http Server | 2.4.26 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/99568Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1038907Third Party AdvisoryVDB Entry
- https://httpd.apache.org/security/vulnerabilities_24.htmlRelease NotesVendor Advisory
- https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cd
- https://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e10
- https://lists.apache.org/thread.html/9d0098775bd83cf7c33ac5a077ef412c14ce9391989
- https://lists.apache.org/thread.html/r15f9aa4427581a1aecb4063f1b4b983511ae1c9935
- https://lists.apache.org/thread.html/r476d175be0aaf4a17680ef98c5153b4d336eaef76f
- https://lists.apache.org/thread.html/r6521a7f62276340eabdb3339b2aa9a38c5f59d9784
- https://lists.apache.org/thread.html/r76142b8c5119df2178be7c2dba88fde552eedeec37
- https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f8
- https://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa
- https://lists.apache.org/thread.html/rcc44594d4d6579b90deccd4536b5d31f099ef563df
- https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0
- https://lists.apache.org/thread.html/rd336919f655b7ff309385e34a143e41c503e133da8
FAQ
What is CVE-2017-9789?
CVE-2017-9789 is a vulnerability with a CVSS score of 7.5 (HIGH). When under stress, closing many connections, the HTTP/2 handling code in Apache httpd 2.4.26 would sometimes access memory after it has been freed, resulting in potentially erratic behaviour.
How severe is CVE-2017-9789?
CVE-2017-9789 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-9789?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Http Server.