Improper input validation in Apache HTTP Server - CVE-2018-8011

 

Improper input validation in Apache HTTP Server - CVE-2018-8011

Published: July 18, 2018


Vulnerability identifier: #VU13907
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-8011
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform denial of service (DoS) attack.

The vulnerability exists due to improper filtering of input data within "mod_md" apache module when processing requests. A remote attacker can send a specially crafted HTTP request to the affected web server and trigger denial of service condition via coredumps.



Affected software

Apache HTTP Server
Arch Linux
Amazon Linux AMI
Slackware Linux
Opensuse
Fedora
apache2 (Alpine package)
httpd

How to mitigate CVE-2018-8011

Update to version 2.4.34.

Apache HTTP Server - update to 2.4.34
apache2 (Alpine package) - update to 2.4.34-r0
httpd - addressed in versions 2.4.34-3.fc27, 2.4.34-3.fc28

External References

Related Security Bulletins