• Services
    • Asses
      • Compromise Assessment
      • APT Assessment
      • Penetration Testing
      • Secure Architecture Design & Review
      • Red Team Assessment
      • Purple Team Assessment
      • Social Engineering
      • Source Code Review
    • Transform
      • SOC Consultancy
      •     SOC Maturity Assessment
      •     SOC Model Evaluation
      •     SOC Gap Analysis
      •     SIEM Gap Analysis
      •     SIEM Optimization
      •     SOC Content Pack
    • Train
      • Security Awareness and Training
      • Tabletop Exercise
      • Simulated Cyber Attack Exercises
    • Respond
      • Incident Response
      • Incident Analysis
  • Managed Security
    • Managed Security Monitoring
      • Remote SOC
      • Onsite SOC
      • Hybrid SOC
    • Managed Security Services
      • Managed Detection and Response
      • Managed Endpoint Detection and Response
      • Managed Threat Intelligence
      • Managed Threat Hunting
      • Managed Risk-Based SOAR
      • Managed Penetration Testing
  • Solutions
  • Resources
    • Blog
    • Threat Advisory
  • Company
    • About Us
    • Careers
    • Contact
Rewterz Threat Advisory – Microsoft Windows 7 Jet Database Engine Out-Of-Bounds Memory Access Vulnerability
September 25, 2018
Rewterz Threat Advisory – CVE-2018-1820 – IBM WebSphere Portal Cross-Site Scripting Vulnerability
September 26, 2018

Rewterz Threat Advisory – CVE-2018-11763 – Apache HTTP Server SETTINGS Frames Denial of Service Vulnerability

September 26, 2018

A vulnerability has been reported in Apache HTTP Server, which can be exploited by malicious people to cause a DoS (Denial of Service).

 

 

IMPACT:  NORMAL

 

 

PUBLISH DATE: 26-09-2018

 

 

OVERVIEW

 

 

In Apache HTTP Server 2.4.17 to 2.4.34, an attacker could induce a Denial of Service by sending continuous SETTINGS frames of maximum size on an ongoing HTTP/2 connection. It will keep the connection busy and will prevent it from timing out. This can be abused for a DoS on the server. Only servers that have enabled the h2 protocol can be affected.

 

 

ANALYSIS

 

 

A vulnerability is found in some versions of the Apache HTTP Server that may lead to a Denial of Service condition. This error affects an unknown function of the component SETTINGS Frame Handler.

 

 

When handling SETTINGS frames of maximum size an ongoing HTTP/2 connection can be exploited. The connection won’t time out, and may cause Denial of Service. It impacts the availability of an organization.

 

 

However, successful exploitation of this error requires that h2 protocol is enabled in the server. This network vulnerability does not require any privileges or user interaction to be exploited.

 

 

 

AFFECTED PRODUCTS

 

 

Apache HTTP Server 2.4.x

 

(The vulnerability is reported in versions 2.4.34, 2.4.33, 2.4.30, 2.4.29, 2.4.28, 2.4.27, 2.4.26, 2.4.25, 2.4.23, 2.4.20, and 2.4.18.)

 

(The httpd packages in Red Hat Enterprise Linux 7 and earlier do not include support for HTTP/2 and hence are not affected by this issue.)

 

 

UPDATES

Update to version 2.4.35. Refer to links for further help.

http://httpd.apache.org/download.cgi

https://websiteforstudents.com/apache2-http-server-2-4-35-released-heres-how-to-install-upgrade-on-ubuntu-16-04-18-04-lts/

 

 

MITIGATION

Apart from updating to the patched version, another possible mitigation is to not enable the h2 protocol.

 

 

If you think you are a victim of a cyberattack, immediately send an email to info@rewterz.com.

 

  • Services
    • Asses
      • Compromise Assessment
      • APT Assessment
      • Penetration Testing
      • Secure Architecture Design & Review
      • Red Team Assessment
      • Purple Team Assessment
      • Social Engineering
      • Source Code Review
    • Respond
      • Incident Response
      • Incident Analysis
  • Transform
    • SOC Consultancy
    •     SOC Maturity Assessment
    •     SOC Model Evaluation
    •     SOC Gap Analysis
    •     SIEM Gap Analysis
    •     SIEM Optimization
    •     SOC Content Pack
  • Train
    • Security Awareness and Training
    • Tabletop Exercise
    • Simulated Cyber Attack Exercises
  • Managed Security
    • Managed Security Monitoring
      • Remote SOC
      • Onsite SOC
      • Hybrid SOC
    • Managed Security Services
      • Managed Detection and Response
      • Managed Endpoint Detection and Response
      • Managed Threat Intelligence
      • Managed Threat Hunting
      • Managed Risk-Based SOAR
      • Managed Penetration Testing
  • Solutions
  • Resources
    • Blog
    • Threat Advisory
  • Company
    • About Us
    • Careers
    • Contact
COPYRIGHT © REWTERZ. ALL RIGHTS RESERVED.