PT-2018-1588 · Apache+3 · Apache Http Server+3

Gal Goldshtein

·

Published

2018-09-25

·

Updated

2024-06-15

·

CVE-2018-11763

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Apache HTTP Server versions 2.4.17 through 2.4.34
Description The issue is related to insufficient input validation in the Apache HTTP Server, which can be exploited by a remote attacker to cause a denial of service by exhausting the limit of simultaneously open connections through continuous sending of maximum-sized SETTINGS frames. This affects only HTTP/2 connections.
Recommendations For Apache HTTP Server versions 2.4.17 through 2.4.34, a possible mitigation is to not enable the h2 protocol.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2385
BDU:2018-01145
CVE-2018-11763
MGASA-2018-0460
OPENSUSE-SU-2018_3185-1
OPENSUSE-SU-2018_3713-1
OPENSUSE-SU-2019:1547-1
OPENSUSE-SU-2019:1814-1
OPENSUSE-SU-2019_0084-1
OPENSUSE-SU-2019_1547-1
OPENSUSE-SU-2019_1814-1
OPENSUSE-SU-2024:11501-1
RHSA-2018:3558
RHSA-2019:0367
SUSE-SU-2018:3101-1
SUSE-SU-2018:3582-1
SUSE-SU-2018:3582-2
SUSE-SU-2018_3101-1
SUSE-SU-2018_3582-1
SUSE-SU-2018_3582-2
USN-3783-1
ZDI-18-1369

Affected Products

Alt Linux
Apache Http Server
Suse
Ubuntu