CVE-2018-1302
Publication date 26 March 2018
Last updated 24 July 2024
Ubuntu priority
Cvss 3 Severity Score
When an HTTP/2 stream was destroyed after being handled, the Apache HTTP Server prior to version 2.4.30 could have written a NULL pointer potentially to an already freed memory. The memory pools maintained by the server make this vulnerability hard to trigger in usual configurations, the reporter and the team could not reproduce it outside debug builds, so it is classified as low risk.
Status
Package | Ubuntu Release | Status |
---|---|---|
apache2 | 18.04 LTS bionic |
Fixed 2.4.29-1ubuntu4.4
|
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty |
Not affected
|
Notes
mdeslaur
artful and older don't enable http2 in the build. this needs to be fixed by backporting the whole http2 module from a more-recent apache2
Patch details
Package | Patch details |
---|---|
apache2 |
|
Severity score breakdown
Parameter | Value |
---|---|
Base score | 5.9 · Medium |
Attack vector | Network |
Attack complexity | High |
Privileges required | None |
User interaction | None |
Scope | Unchanged |
Confidentiality | None |
Integrity impact | None |
Availability impact | High |
Vector | CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H |
References
Related Ubuntu Security Notices (USN)
- USN-3783-1
- Apache HTTP Server vulnerabilities
- 3 October 2018