Related Vulnerabilities: CVE-2017-9789  

A security issue has been found in apache's mod_http2 <= 2.4.26. When under stress, closing many connections, the HTTP/2 handling code would sometimes access memory after it has been freed, resulting in potentially erratic behaviour.

Severity Critical

Remote Yes

Type Arbitrary code execution

Description

A security issue has been found in apache's mod_http2 <= 2.4.26. When under stress, closing many connections, the HTTP/2 handling code would sometimes access memory after it has been freed, resulting in potentially erratic behaviour.

AVG-350 apache 2.4.26-3 2.4.27-1 Critical Fixed

14 Jul 2017 ASA-201707-15 AVG-350 apache Critical multiple issues

https://httpd.apache.org/security/vulnerabilities_24.html