CVE-2018-1302

Modified
Published: 26 Mar 2018, 15:00
Last modified:17 Sept 2024, 02:41

Vulnerability Summary

Overall Risk (default)
medium
26/100
CVSS Score
5.9 MEDIUM
v3.0 (nvd)
EPSS Score
12.13% MEDIUM
12% probability +1.12%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

26 Mar 2018, 15:00
Published
Vulnerability first disclosed
17 Sept 2024, 02:41
Last Modified
Vulnerability information updated

Description

When an HTTP/2 stream was destroyed after being handled, the Apache HTTP Server prior to version 2.4.30 could have written a NULL pointer potentially to an already freed memory. The memory pools maintained by the server make this vulnerability hard to trigger in usual configurations, the reporter and the team could not reproduce it outside debug builds, so it is classified as low risk.

CVSS Metrics

  • v3.0MEDIUMScore: 5.9CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
  • v2.0MEDIUMScore: 4.3AV:N/AC:M/Au:N/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 12.13% Percentile: 94%

Techniques & Countermeasures

  • CWE-476NULL Pointer Dereference

    The product dereferences a pointer that it expects to be valid but is NULL.

Affected Systems

  • apache software foundationapache http server

    2.4.17 to 2.4.29

  • UnknownHTTP Server

    ≤ 2.4.29

  • canonicalubuntu_linux

    18.04

  • netappclustered_data_ontap

    na

  • netappsantricity_cloud_connector

    na

  • netappstorage_automation_store

    na

  • netappstoragegrid

    na

References (23)