Null pointer dereference in Apache HTTP Server - CVE-2018-1302
Published: March 27, 2018 / Updated: July 20, 2018
Vulnerability identifier: #VU11287
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1302
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The weakness exists due to improper destruction of an HTTP/2 stream after being handled. A remote attacker can send a specially crafted HTTP/2 stream, write a NULL pointer value to an already freed memory space and cause the service to crash.
The weakness exists due to improper destruction of an HTTP/2 stream after being handled. A remote attacker can send a specially crafted HTTP/2 stream, write a NULL pointer value to an already freed memory space and cause the service to crash.
Affected software
Apache HTTP Server
Amazon Linux AMI
Arch Linux
Fedora
Tenable.sc
apache2 (Alpine package)
mod_http2
Dell Secure Connect Gateway
Amazon Linux AMI
Arch Linux
Fedora
Tenable.sc
apache2 (Alpine package)
mod_http2
Dell Secure Connect Gateway
How to mitigate CVE-2018-1302
Update to version 2.4.32.
Apache HTTP Server - update to 2.4.32
Tenable.sc - update to 5.13.0
apache2 (Alpine package) - update to 2.4.33-r0
Dell Secure Connect Gateway - update to 5.12.00.10
mod_http2 - addressed in versions 1.10.16-1.fc26, 1.10.16-1.fc27, 1.10.16-1.fc28, 1.10.18-1.fc26
Tenable.sc - update to 5.13.0
apache2 (Alpine package) - update to 2.4.33-r0
Dell Secure Connect Gateway - update to 5.12.00.10
mod_http2 - addressed in versions 1.10.16-1.fc26, 1.10.16-1.fc27, 1.10.16-1.fc28, 1.10.18-1.fc26
External References
Related Security Bulletins
- Multiple vulnerabilities in Apache HTTP Server
- Arch Linux update for apache
- Amazon Linux AMI update for httpd24
- Multiple vulnerabilities in Tenable.sc
- Null pointer dereference in apache2 (Alpine package)
- Multiple vulnerabilities in DELL Secure Connect Gateway Security
- Fedora 28 update for mod_http2
- Fedora 26 update for mod_http2
- Fedora 27 update for mod_http2
- Fedora 26 update for mod_http2