CVE-2018-1301

Description

A specially crafted request could have crashed the Apache HTTP Server prior to version 2.4.30, due to an out of bound access after a size limit is reached by reading the HTTP header. This vulnerability is considered very hard if not impossible to trigger in non-debug mode (both log and build level), so it is classified as low risk for common server usage.

Risk Information

Base Score
5.9
MODERATE
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
6.762

Associated Vulnerability

VulnerabilityOS Platform
Update Apache to version 2.4.33Windows
Multiple vulnerabilities are fixed in Apache 2.4.33Windows
Multiple Vulnerabilities are affected in IBM Tivoli Monitoring 6.2.3Windows
Multiple Vulnerabilities are affected in IBM Tivoli Monitoring 6.3.0Windows
Apache HTTP server (USN-3425-1) apache2-bin_2.4.18-2ubuntu3.8_amd64.debLinux
Apache HTTP server (USN-3425-1) apache2-bin_2.4.18-2ubuntu3.8_i386.debLinux
Apache HTTP server (USN-3370-1) apache2-bin_2.4.18-2ubuntu3.8_amd64.debLinux
Apache HTTP server (USN-3370-1) apache2-bin_2.4.18-2ubuntu3.8_i386.debLinux
Apache HTTP server (USN-3627-1) apache2-bin_2.4.18-2ubuntu3.8_i386.debLinux
Apache HTTP server (USN-3627-1) apache2-bin_2.4.18-2ubuntu3.8_amd64.debLinux
Apache HTTP server (USN-3627-1) apache2-bin_2.4.7-1ubuntu4.20_i386.debLinux
Apache HTTP server (USN-3627-1) apache2-bin_2.4.7-1ubuntu4.20_amd64.debLinux
Apache HTTP server (USN-3627-2) apache2-bin_2.4.29-1ubuntu4.1_i386.debLinux
Apache HTTP server (USN-3627-2) apache2-bin_2.4.29-1ubuntu4.1_amd64.debLinux
apache2 security update(DSA-4164-1) apache2_2.4.25-3+deb9u4_i386.debLinux
apache2 security update(DSA-4164-1) apache2_2.4.25-3+deb9u4_amd64.debLinux
SUSE-SU-2018:1079-1(SUSE Linux Enterprise Server 11-SP4 ) apache2-2.2.34-70.15.1.x86_64.rpmLinux
SUSE-SU-2018:1079-1(SUSE Linux Enterprise Server 11-SP4 ) apache2-doc-2.2.34-70.15.1.x86_64.rpmLinux
SUSE-SU-2018:1079-1(SUSE Linux Enterprise Server 11-SP4 ) apache2-example-pages-2.2.34-70.15.1.x86_64.rpmLinux
SUSE-SU-2018:1079-1(SUSE Linux Enterprise Server 11-SP4 ) apache2-prefork-2.2.34-70.15.1.x86_64.rpmLinux
SUSE-SU-2018:1079-1(SUSE Linux Enterprise Server 11-SP4 ) apache2-utils-2.2.34-70.15.1.x86_64.rpmLinux
SUSE-SU-2018:1079-1(SUSE Linux Enterprise Server 11-SP4 ) apache2-worker-2.2.34-70.15.1.x86_64.rpmLinux
(RHSA-2020:1121) httpd security, bug fix, and enhancement update httpd-2.4.6-93.el7.x86_64.rpmLinux
(RHSA-2020:1121) httpd security, bug fix, and enhancement update httpd-devel-2.4.6-93.el7.x86_64.rpmLinux
(RHSA-2020:1121) httpd security, bug fix, and enhancement update httpd-manual-2.4.6-93.el7.noarch.rpmLinux
(RHSA-2020:1121) httpd security, bug fix, and enhancement update httpd-tools-2.4.6-93.el7.x86_64.rpmLinux
(RHSA-2020:1121) httpd security, bug fix, and enhancement update mod_ldap-2.4.6-93.el7.x86_64.rpmLinux
(RHSA-2020:1121) httpd security, bug fix, and enhancement update mod_proxy_html-2.4.6-93.el7.x86_64.rpmLinux
(RHSA-2020:1121) httpd security, bug fix, and enhancement update mod_session-2.4.6-93.el7.x86_64.rpmLinux
(RHSA-2020:1121) httpd security, bug fix, and enhancement update mod_ssl-2.4.6-93.el7.x86_64.rpmLinux
Update Apache to version 2.4.33 (For Linux)Linux
Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (CVE-2018-1301)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234