Improper input validation in Apache HTTP Server - CVE-2018-1333
Published: July 18, 2018
Vulnerability identifier: #VU13908
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1333
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service attack.
The vulnerability exists due to insufficient filtering of incoming data within "mod_http2" apache module. A remote attacker can send a specially crafted HTTP request to the affected web server and trigger daemon crash.
Affected software
Apache HTTP Server
Arch Linux
Slackware Linux
Opensuse
Fedora
Tenable.sc
apache2 (Alpine package)
httpd
Dell Secure Connect Gateway
Arch Linux
Slackware Linux
Opensuse
Fedora
Tenable.sc
apache2 (Alpine package)
httpd
Dell Secure Connect Gateway
How to mitigate CVE-2018-1333
Update to version 2.4.34.
Apache HTTP Server - update to 2.4.34
Tenable.sc - update to 5.13.0
apache2 (Alpine package) - update to 2.4.34-r0
Dell Secure Connect Gateway - update to 5.12.00.10
httpd - update to 2.4.34-3.fc28
Tenable.sc - update to 5.13.0
apache2 (Alpine package) - update to 2.4.34-r0
Dell Secure Connect Gateway - update to 5.12.00.10
httpd - update to 2.4.34-3.fc28
External References
Related Security Bulletins
- Remote denial of service in Apache HTTP server
- Slackware Linux update for httpd
- Arch Linux update for apache
- OpenSUSE Linux update for apache2
- OpenSUSE Linux update for apache2
- Multiple vulnerabilities in Tenable.sc
- Improper input validation in apache2 (Alpine package)
- Multiple vulnerabilities in DELL Secure Connect Gateway Security
- Fedora 28 update for httpd