Description
The HTTP/2 experimental feature in Apache Traffic Server 5.3.x before 5.3.1 allows remote attackers to cause a denial of service (out-of-bounds access and daemon crash) or possibly execute arbitrary code via vectors related to the (1) frame_handlers array or (2) set_dynamic_table_size function.
Remediation
References
Related Vulnerabilities
Oracle Database Server Other Vulnerability (CVE-2001-0515)
WordPress Plugin Super Forms-Drag & Drop Form Builder Arbitrary File Upload (4.9.700)
Oracle Application Server Other Vulnerability (CVE-2007-2121)
Roundcube Incorrect Resource Transfer Between Spheres Vulnerability (CVE-2026-35542)
WordPress Plugin Simple Video Embedder Cross-Site Scripting (2.2)