CVE-2018-1330
published 2018-09-13CVE-2018-1330: When parsing a malformed JSON payload, libprocess in Apache Mesos versions 1.4.0 to 1.5.0 might crash due to an uncaught exception. Parsing chunked HTTP…
PriorityP336high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
3.67%
88.4th percentile
When parsing a malformed JSON payload, libprocess in Apache Mesos versions 1.4.0 to 1.5.0 might crash due to an uncaught exception. Parsing chunked HTTP requests with trailers can lead to a libprocess crash too because of the mistakenly planted assertion. A malicious actor can therefore cause a denial of service of Mesos masters rendering the Mesos-controlled cluster inoperable.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | mesos | — | — |
| apache | mesos | — | — |
| apache | mesos | >= 1.4.0 < 1.4.2 | 1.4.2 |
| apache | mesos | >= 1.5.0 < 1.5.1 | 1.5.1 |
| apache_software_foundation | apache_mesos | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Crash when decoding malformed HTTP requests or malformed JSON payload
osv·2022-05-14
CVE-2018-1330 [HIGH] Crash when decoding malformed HTTP requests or malformed JSON payload
Crash when decoding malformed HTTP requests or malformed JSON payload
When parsing a malformed JSON payload, libprocess in Apache Mesos versions 1.4.0 to 1.5.0 might crash due to an uncaught exception. Parsing chunked HTTP requests with trailers can lead to a libprocess crash too because of the mistakenly planted assertion. A malicious actor can therefore cause a denial of service of Mesos masters rendering the Mesos-controlled cluster inoperable.
GHSA
Crash when decoding malformed HTTP requests or malformed JSON payload
ghsa·2022-05-14
CVE-2018-1330 [HIGH] CWE-248 Crash when decoding malformed HTTP requests or malformed JSON payload
Crash when decoding malformed HTTP requests or malformed JSON payload
When parsing a malformed JSON payload, libprocess in Apache Mesos versions 1.4.0 to 1.5.0 might crash due to an uncaught exception. Parsing chunked HTTP requests with trailers can lead to a libprocess crash too because of the mistakenly planted assertion. A malicious actor can therefore cause a denial of service of Mesos masters rendering the Mesos-controlled cluster inoperable.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-1330 mesos: Libprocess crashes when decoding malformed HTTP requests or malformed JSON payload
bugzilla·2018-09-17·CVSS 7.5
CVE-2018-1330 [HIGH] CVE-2018-1330 mesos: Libprocess crashes when decoding malformed HTTP requests or malformed JSON payload
CVE-2018-1330 mesos: Libprocess crashes when decoding malformed HTTP requests or malformed JSON payload
When parsing a malformed JSON payload, libprocess in Apache Mesos versions 1.4.0 to 1.5.0 might crash due to an uncaught exception. Parsing chunked HTTP requests with trailers can lead to a libprocess crash too because of the mistakenly planted assertion. A malicious actor can therefore cause a denial of service of Mesos masters rendering the Mesos-controlled cluster inoperable.
References:
https://lists.apache.org/thread.html/395cb6bcf367702acd1e580a1f39b56cdd7a5953d0368b4c1adb1dde@%3Cdev.mesos.apache.org%3E
Discussion:
Created mesos tracking bugs for this issue:
Affects: fedora-all [bug 1629965]
---
This CVE Bugzilla entry is for community support informational purposes only as
Bugzilla
CVE-2018-1330 mesos: Libprocess crashes when decoding malformed HTTP requests or malformed JSON payload [fedora-all]
bugzilla·2018-09-17·CVSS 7.5
CVE-2018-1330 [HIGH] CVE-2018-1330 mesos: Libprocess crashes when decoding malformed HTTP requests or malformed JSON payload [fedora-all]
CVE-2018-1330 mesos: Libprocess crashes when decoding malformed HTTP requests or malformed JSON payload [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this is
2018-09-13
Published