Improper input validation in Apache HTTP Server - CVE-2018-1333

 

Improper input validation in Apache HTTP Server - CVE-2018-1333

Published: July 18, 2018


Vulnerability identifier: #VU13908
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1333
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service attack.

The vulnerability exists due to insufficient filtering of incoming data within "mod_http2" apache module. A remote attacker can send a specially crafted HTTP request to the affected web server and trigger daemon crash.


Affected software

Apache HTTP Server
Arch Linux
Slackware Linux
Opensuse
Fedora
Tenable.sc
apache2 (Alpine package)
httpd
Dell Secure Connect Gateway

How to mitigate CVE-2018-1333

Update to version 2.4.34.

Apache HTTP Server - update to 2.4.34
Tenable.sc - update to 5.13.0
apache2 (Alpine package) - update to 2.4.34-r0
Dell Secure Connect Gateway - update to 5.12.00.10
httpd - update to 2.4.34-3.fc28

External References

Related Security Bulletins