Vulnerability CVE-2018-1302


Published: 2018-03-26

Description:
When an HTTP/2 stream was destroyed after being handled, the Apache HTTP Server prior to version 2.4.30 could have written a NULL pointer potentially to an already freed memory. The memory pools maintained by the server make this vulnerability hard to trigger in usual configurations, the reporter and the team could not reproduce it outside debug builds, so it is classified as low risk.

Type:

CWE-476

(NULL Pointer Dereference)

CVSS2 => (AV:N/AC:M/Au:N/C:N/I:N/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4.3/10
2.9/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
None
None
Partial
Affected software
Netapp -> Clustered data ontap 
Netapp -> Santricity cloud connector 
Netapp -> Storage automation store 
Netapp -> Storagegrid 
Debian -> Debian linux 
Canonical -> Ubuntu linux 
Apache -> Http server 

 References:
http://www.openwall.com/lists/oss-security/2018/03/24/5
http://www.securityfocus.com/bid/103528
http://www.securitytracker.com/id/1040567
https://access.redhat.com/errata/RHSA-2019:0366
https://access.redhat.com/errata/RHSA-2019:0367
https://httpd.apache.org/security/vulnerabilities_24.html
https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba@%3Ccvs.httpd.apache.org%3E
https://security.netapp.com/advisory/ntap-20180601-0004/
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03909en_us
https://usn.ubuntu.com/3783-1/

Copyright 2024, cxsecurity.com

 

Back to Top