File _patchinfo of Package patchinfo.8948
<patchinfo incident="8948"> <issue tracker="bnc" id="1109961">VUL-0: CVE-2018-11763: apache2: DoS for HTTP/2 connections by continuous SETTINGS</issue> <issue tracker="cve" id="2018-11763"/> <category>security</category> <rating>important</rating> <packager>pgajdos</packager> <description>This update for apache2 fixes the following issues: Security issues fixed: - CVE-2018-11763: In Apache HTTP Server by sending continuous, large SETTINGS frames a client can occupy a connection, server thread and CPU time without any connection timeout coming to effect. This affects only HTTP/2 connections. (bsc#1109961) Bug fixes: - consider also patterns in APACHE_CONF_INCLUDE_DIRS as documentation says (patch Juergen Gleiss) </description> <summary>Security update for apache2</summary> </patchinfo>