Discussion:
Bug#909591: apache2: CVE-2018-11763: mod_http2, DoS via continuous SETTINGS frames
Salvatore Bonaccorso
2018-09-25 18:57:06 UTC
Permalink
Source: apache2
Version: 2.4.25-1
Severity: important
Tags: security upstream

Hi,

The following vulnerability was published for apache2.

CVE-2018-11763[0]:
mod_http2, DoS via continuous SETTINGS frames

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2018-11763
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-11763
[1] https://lists.apache.org/thread.html/d435b0267a76501b9e06c552b20c887171064cde38e46d678da4d3dd@%3Cannounce.httpd.apache.org%3E

Regards,
Salvatore
Nuno Paquete
2018-09-26 06:15:20 UTC
Permalink
Hi Salvatore,

Please help me to unsubscribe these emails, I'm trying for several weeks to
do it, but no success.

Many thanks in advance for your support.
Nuno Paquete
Post by Salvatore Bonaccorso
Source: apache2
Version: 2.4.25-1
Severity: important
Tags: security upstream
Hi,
The following vulnerability was published for apache2.
mod_http2, DoS via continuous SETTINGS frames
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
[0] https://security-tracker.debian.org/tracker/CVE-2018-11763
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-11763
[1]
Regards,
Salvatore
Debian Bug Tracking System
2018-10-07 11:36:06 UTC
Permalink
Your message dated Sun, 07 Oct 2018 11:34:26 +0000
with message-id <E1g97KM-000Gpl-***@fasolo.debian.org>
and subject line Bug#909591: fixed in apache2 2.4.35-1
has caused the Debian Bug report #909591,
regarding apache2: CVE-2018-11763: mod_http2, DoS via continuous SETTINGS frames
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ***@bugs.debian.org
immediately.)
--
909591: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=909591
Debian Bug Tracking System
Contact ***@bugs.debian.org with problems
Debian Bug Tracking System
2018-11-04 11:51:20 UTC
Permalink
Your message dated Sun, 04 Nov 2018 11:47:09 +0000
with message-id <E1gJGs1-000G9z-***@fasolo.debian.org>
and subject line Bug#909591: fixed in apache2 2.4.25-3+deb9u6
has caused the Debian Bug report #909591,
regarding apache2: CVE-2018-11763: mod_http2, DoS via continuous SETTINGS frames
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact ***@bugs.debian.org
immediately.)
--
909591: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=909591
Debian Bug Tracking System
Contact ***@bugs.debian.org with problems
Loading...