Input validation error in Apache HTTP Server - CVE-2018-17189
Published: January 23, 2019 / Updated: January 24, 2019
Vulnerability identifier: #VU17177
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-17189
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The weakness exists due to an error when handling malicious input. A remote attacker can send a specially crafted request bodies in a slow loris way to plain resources and cause the h2 stream for that request unnecessarily occupied a server thread cleaning up that incoming data.
The weakness exists due to an error when handling malicious input. A remote attacker can send a specially crafted request bodies in a slow loris way to plain resources and cause the h2 stream for that request unnecessarily occupied a server thread cleaning up that incoming data.
Affected software
Apache HTTP Server
Amazon Linux AMI
Gentoo Linux
Arch Linux
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Slackware Linux
Opensuse
Fedora
JBoss Core Services
Tenable.sc
Red Hat Software Collections
apache2 (Debian package)
apache2 (Ubuntu package)
apache2 (Alpine package)
mod_http2
Dell Secure Connect Gateway
Maximo Application Suite - IoT Component
Amazon Linux AMI
Gentoo Linux
Arch Linux
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Slackware Linux
Opensuse
Fedora
JBoss Core Services
Tenable.sc
Red Hat Software Collections
apache2 (Debian package)
apache2 (Ubuntu package)
apache2 (Alpine package)
mod_http2
Dell Secure Connect Gateway
Maximo Application Suite - IoT Component
How to mitigate CVE-2018-17189
Update to version 2.4.38.
Apache HTTP Server - update to 2.4.38
Tenable.sc - update to 5.13.0
apache2 (Debian package) - update to 2.4.25-3+deb9u7
apache2 (Ubuntu package) - addressed in versions 2.4.7-1ubuntu4.22, 2.4.18-2ubuntu3.10, 2.4.29-1ubuntu4.6, 2.4.34-1ubuntu2.1
apache2 (Alpine package) - update to 2.4.38-r0
Dell Secure Connect Gateway - update to 5.12.00.10
mod_http2 - addressed in versions 1.14.1-1.fc28, 1.14.1-1.fc29, 1.14.1-1.fc30
Maximo Application Suite - IoT Component - addressed in versions 8.7.20, 8.8.16, 9.0.6
Tenable.sc - update to 5.13.0
apache2 (Debian package) - update to 2.4.25-3+deb9u7
apache2 (Ubuntu package) - addressed in versions 2.4.7-1ubuntu4.22, 2.4.18-2ubuntu3.10, 2.4.29-1ubuntu4.6, 2.4.34-1ubuntu2.1
apache2 (Alpine package) - update to 2.4.38-r0
Dell Secure Connect Gateway - update to 5.12.00.10
mod_http2 - addressed in versions 1.14.1-1.fc28, 1.14.1-1.fc29, 1.14.1-1.fc30
Maximo Application Suite - IoT Component - addressed in versions 8.7.20, 8.8.16, 9.0.6
External References
Related Security Bulletins
- Multiple vulnerabilities in Apache HTTP Server
- Slackware Linux update for httpd
- Arch Linux update for apache
- Debian update for apache2
- Ubuntu update for Apache HTTP Server
- OpenSUSE Linux update for apache2
- OpenSUSE Linux update for apache2
- Amazon Linux AMI update for httpd24
- Gentoo update for Apache
- Red Hat JBoss Core Services update for Apache HTTP Server 2.4.37
- Red Hat JBoss Core Services update for Apache HTTP Server 2.4.37 (RHEL 6)
- Red Hat JBoss Core Services update Apache HTTP Server 2.4.37 (RHEL 7)
- Red Hat Software Collections update for httpd24-httpd
- Multiple vulnerabilities in Tenable.sc
- Input validation error in apache2 (Alpine package)
- Red Hat Enterprise Linux 8 update for the httpd:2.4 module
- Multiple vulnerabilities in DELL Secure Connect Gateway Security
- Multiple vulnerabilities in IBM Maximo Application Suite - IoT Component
- Fedora 28 update for mod_http2
- Fedora 29 update for mod_http2
- Fedora 30 update for mod_http2