PT-2018-3638 · Apache+2 · Apache Http Server+2

Daniel Caminada

·

Publicado

2018-03-09

·

Atualizado

2021-06-06

·

CVE-2018-8011

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Apache HTTP Server version 2.4.33
Description The issue is related to the mod md challenge handler, which can dereference a NULL pointer when specially crafted HTTP requests are made, causing the child process to segfault. This can be used to cause a denial of service (DoS) to the server.
Recommendations For Apache HTTP Server version 2.4.33, update to version 2.4.34 to resolve the issue. As a temporary workaround, consider restricting access to the mod md module to minimize the risk of exploitation.

Correção

DoS

NULL Pointer Dereference

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-2068
BDU:2021-01497
CVE-2018-8011
OPENSUSE-SU-2018_2433-1
SUSE-SU-2018:2424-1

Produtos afetados

Alt Linux
Apache Http Server
Suse