CVE-2016-1546

Related Vulnerabilities: CVE-2016-1546  

A denial of service flaw was found in httpd's mod_http2 module. A remote attacker could use this flaw to block server threads for long times, causing starvation of worker threads, by manipulating the flow control windows on streams.

A denial of service flaw was found in httpd's mod_http2 module. A remote attacker could use this flaw to block server threads for long times, causing starvation of worker threads, by manipulating the flow control windows on streams.

Find out more about CVE-2016-1546 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v2 metrics

Base Score 4.3
Base Metrics AV:N/AC:M/Au:N/C:N/I:N/A:P
Access Vector Network
Access Complexity Medium
Authentication None
Confidentiality Impact None
Integrity Impact None
Availability Impact Partial

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Red Hat Security Errata

Platform Errata Release Date
Red Hat Software Collections for Red Hat Enterprise Linux 7 (httpd24-httpd) RHSA-2017:1161 2017-04-26
Red Hat Software Collections for Red Hat Enterprise Linux 6 (httpd24-httpd) RHSA-2017:1161 2017-04-26

Affected Packages State

Platform Package State
Red Hat JBoss Web Server 3.0 httpd Not affected
Red Hat JBoss EWS 2 httpd Not affected
Red Hat JBoss EWS 1 httpd Not affected
Red Hat JBoss EAP 6 httpd Not affected
Red Hat JBoss EAP 5 httpd Not affected
Red Hat Enterprise Linux 7 httpd Not affected
Red Hat Enterprise Linux 6 httpd Not affected
Red Hat Enterprise Linux 5 httpd Not affected
Red Hat Directory Server 8 httpd Not affected

External References