CVE-2018-1303
Last modified
CVE-2018-1303 is a vulnerability of currently unknown severity. A specially crafted HTTP request header could have crashed the Apache HTTP Server prior to version 2.4.30 due to an out of bound read while preparing data to be cached in shared memory. It could be used as a Denial of Service attack against users of mod_cache_socache. EPSS estimates a 70.78% chance of exploitation in the next 30 days.
Description
A specially crafted HTTP request header could have crashed the Apache HTTP Server prior to version 2.4.30 due to an out of bound read while preparing data to be cached in shared memory. It could be used as a Denial of Service attack against users of mod_cache_socache. The vulnerability is considered as low risk since mod_cache_socache is not widely used, mod_cache_disk is not concerned by this vulnerability.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Http Server | <= 2.4.29 |
| Debian | Debian Linux | 8.0 |
| Debian | Debian Linux | 9.0 |
| Canonical | Ubuntu Linux | 14.04 |
| Canonical | Ubuntu Linux | 16.04 |
| Canonical | Ubuntu Linux | 17.10 |
| Canonical | Ubuntu Linux | 18.04 |
| Netapp | Santricity Cloud Connector | All versions |
| Netapp | Storage Automation Store | All versions |
| Netapp | Storagegrid | All versions |
| Netapp | Clustered Data Ontap | All versions |
References
- http://www.openwall.com/lists/oss-security/2018/03/24/3Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/103522Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040572Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:3558Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:0366Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:0367Third Party Advisory
- https://httpd.apache.org/security/vulnerabilities_24.htmlVendor Advisory
- https://security.netapp.com/advisory/ntap-20180601-0004/Third Party Advisory
- https://usn.ubuntu.com/3627-1/Third Party Advisory
- https://usn.ubuntu.com/3627-2/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4164Third Party Advisory
- http://www.openwall.com/lists/oss-security/2018/03/24/3Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/103522Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040572Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:3558Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:0366Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:0367Third Party Advisory
- https://httpd.apache.org/security/vulnerabilities_24.htmlVendor Advisory
- https://security.netapp.com/advisory/ntap-20180601-0004/Third Party Advisory
- https://usn.ubuntu.com/3627-1/Third Party Advisory
- https://usn.ubuntu.com/3627-2/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4164Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-1303?
How severe is CVE-2018-1303?
How do I fix CVE-2018-1303?
Are you affected by CVE-2018-1303?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
