CVE-2018-1303

CWE-125Out-of-bounds Read12 documents10 sources
Severity
7.5HIGH
EPSS
40.1%
top 2.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 26
Latest updateMay 13

Description

A specially crafted HTTP request header could have crashed the Apache HTTP Server prior to version 2.4.30 due to an out of bound read while preparing data to be cached in shared memory. It could be used as a Denial of Service attack against users of mod_cache_socache. The vulnerability is considered as low risk since mod_cache_socache is not widely used, mod_cache_disk is not concerned by this vulnerability.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

NVDapache/http_server2.4.29
Debianapache2< 2.4.33-1+3

Also affects: Debian Linux 8.0, 9.0, Ubuntu Linux 14.04, 16.04, 17.10, 18.04

🔴Vulnerability Details

4
GHSA
GHSA-8rrj-w45x-2fr2: A specially crafted HTTP request header could have crashed the Apache HTTP Server prior to version 22022-05-13
CVEList
CVE-2018-1303: A specially crafted HTTP request header could have crashed the Apache HTTP Server prior to version 22018-03-26
OSV
CVE-2018-1303: A specially crafted HTTP request header could have crashed the Apache HTTP Server prior to version 22018-03-26
VulnCheck
Apache HTTP Server Out-of-bounds Read2018

💥Exploits & PoCs

1
Exploit-DB
HRSALE The Ultimate HRM 1.0.2 - 'award_id' SQL Injection2018-04-25

📋Vendor Advisories

4
Ubuntu
Apache HTTP Server vulnerabilities2018-04-30
Ubuntu
Apache HTTP Server vulnerabilities2018-04-19
Red Hat
httpd: Out of bounds read in mod_cache_socache can allow a remote attacker to cause DoS2018-03-21
Debian
CVE-2018-1303: apache2 - A specially crafted HTTP request header could have crashed the Apache HTTP Serve...2018

💬Community

2
Bugzilla
CVE-2018-1303 httpd: Out of bounds read in mod_cache_socache can allow a remote attacker to cause a denial of service [fedora-all]2018-03-26
Bugzilla
CVE-2018-1303 httpd: Out of bounds read in mod_cache_socache can allow a remote attacker to cause DoS2018-03-26
CVE-2018-1303 (HIGH CVSS 7.5) | A specially crafted HTTP request he | cvebase.io