PT-2018-11659 · Apache · Apache Traffic Server

Published

2018-08-29

·

Updated

2018-11-07

·

CVE-2018-1318

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Apache Traffic Server (ATS) versions 6.0.0 through 6.2.2 Apache Traffic Server (ATS) versions 7.0.0 through 7.1.3
Description The issue arises when method ACLs are added in remap.config, potentially causing a segfault upon a carefully crafted request.
Recommendations For versions 6.0.0 through 6.2.2, upgrade to version 6.2.3 or later. For versions 7.0.0 through 7.1.3, upgrade to version 7.1.4 or later.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-1318
DSA-4282-1

Affected Products

Apache Traffic Server