Input validation error in Apache HTTP Server - CVE-2018-17189

 

Input validation error in Apache HTTP Server - CVE-2018-17189

Published: January 23, 2019 / Updated: January 24, 2019


Vulnerability identifier: #VU17177
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-17189
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The weakness exists due to an error when handling malicious input. A remote attacker can send a specially crafted request bodies in a slow loris way to plain resources and cause the h2 stream for that request unnecessarily occupied a server thread cleaning up that incoming data. 

Affected software

Apache HTTP Server
Amazon Linux AMI
Gentoo Linux
Arch Linux
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Slackware Linux
Opensuse
Fedora
JBoss Core Services
Tenable.sc
Red Hat Software Collections
apache2 (Debian package)
apache2 (Ubuntu package)
apache2 (Alpine package)
mod_http2
Dell Secure Connect Gateway
Maximo Application Suite - IoT Component

How to mitigate CVE-2018-17189

Update to version 2.4.38.

Apache HTTP Server - update to 2.4.38
Tenable.sc - update to 5.13.0
apache2 (Debian package) - update to 2.4.25-3+deb9u7
apache2 (Ubuntu package) - addressed in versions 2.4.7-1ubuntu4.22, 2.4.18-2ubuntu3.10, 2.4.29-1ubuntu4.6, 2.4.34-1ubuntu2.1
apache2 (Alpine package) - update to 2.4.38-r0
Dell Secure Connect Gateway - update to 5.12.00.10
mod_http2 - addressed in versions 1.14.1-1.fc28, 1.14.1-1.fc29, 1.14.1-1.fc30
Maximo Application Suite - IoT Component - addressed in versions 8.7.20, 8.8.16, 9.0.6

External References

Related Security Bulletins