PT-2018-3634 · Apache+3 · Apache Http Server+3
Published
2018-03-21
·
Updated
2021-06-06
·
CVE-2018-1302
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Apache HTTP Server versions prior to 2.4.33
Description
The issue is related to an HTTP/2 stream vulnerability in the Apache HTTP Server, which is caused by incorrect handling of a NULL pointer. This could potentially allow a remote attacker to cause a denial of service. The vulnerability is considered low risk due to the difficulty in triggering it in usual configurations. The memory pools maintained by the server make exploitation hard, and it was not reproducible outside debug builds.
Recommendations
For versions prior to 2.4.33, update to version 2.4.33 or later to resolve the issue. As a temporary workaround, consider restricting access to HTTP/2 streams until the update is applied.
Fix
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Apache Http Server
Suse
Ubuntu