﻿id	summary	reporter	owner	description	type	status	priority	milestone	component	version	severity	resolution	keywords	cc
8658	Apache httpd-2.4.25 (CVE-2016-0736 CVE-2016-2161 CVE-2016-5387 CVE-2016-8740 CVE-2016-8743)	Pierre Labastie	bdubbs@…	"In dist directory, but not announced yet. The maintainer should be back tomorrow (https://lists.apache.org/list.html?dev@httpd.apache.org:2016-12)


{{{
    CVE-2016-0736 mod_session_crypto: Authenticate the session data/cookie with a MAC (SipHash) to prevent deciphering or tampering with a padding oracle attack.
    CVE-2016-2161 mod_auth_digest: Prevent segfaults during client entry allocation when the shared memory space is exhausted.
    CVE-2016-5387 core: Mitigate [f]cgi ""httpoxy"" issues.
    CVE-2016-8740 mod_http2: Mitigate DoS memory exhaustion via endless CONTINUATION frames.
    CVE-2016-8743 Enforce HTTP request grammar corresponding to RFC7230 for request lines and request headers, to prevent response splitting and cache pollution by malicious clients or downstream proxies.

}}}
"	enhancement	closed	high	8.0	BOOK	SVN	medium	fixed		
