Improper input validation in Apache HTTP Server - CVE-2018-8011
Published: July 18, 2018
Vulnerability details
The vulnerability allows a remote attacker to perform denial of service (DoS) attack.
The vulnerability exists due to improper filtering of input data within "mod_md" apache module when processing requests. A remote attacker can send a specially crafted HTTP request to the affected web server and trigger denial of service condition via coredumps.
Affected software
Arch Linux
Amazon Linux AMI
Slackware Linux
Opensuse
Fedora
apache2 (Alpine package)
httpd
How to mitigate CVE-2018-8011
apache2 (Alpine package) - update to 2.4.34-r0
httpd - addressed in versions 2.4.34-3.fc27, 2.4.34-3.fc28