Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2018-1302


When an HTTP/2 stream was destroyed after being handled, the Apache HTTP Server prior to version 2.4.30 could have written a NULL pointer potentially to an already freed memory. The memory pools maintained by the server make this vulnerability hard to trigger in usual configurations, the reporter and the team could not reproduce it outside debug builds, so it is classified as low risk.


Published

2018-03-26T15:29:00.477

Last Modified

2024-11-21T03:59:34.710

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 5.9 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:N/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-476

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application apache http_server ≤ 2.4.29 Yes
Operating System canonical ubuntu_linux 18.04 Yes
Application netapp clustered_data_ontap - Yes
Application netapp santricity_cloud_connector - Yes
Application netapp storage_automation_store - Yes
Application netapp storagegrid - Yes

References