← All CVEs

CVE-2018-1303

high · 7.5

A specially crafted HTTP request header could have crashed the Apache HTTP Server prior to version 2.4.30 due to an out of bound read while preparing data to be cached in shared memory. It could be used as a Denial of Service attack against users of mod_cache_socache. The vulnerability is considered as low risk since mod_cache_socache is not widely used, mod_cache_disk is not concerned by this vulnerability.

7.5
CVSS
69.8%
EPSS (exploit prob.)
99th
EPSS percentile
2018-03-26
Published

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses

CWE-125

Affected products

VendorProductAffected versions
apachehttp_server<= 2.4.29
debiandebian_linux8.0
debiandebian_linux9.0
canonicalubuntu_linux14.04
canonicalubuntu_linux16.04
canonicalubuntu_linux17.10
canonicalubuntu_linux18.04
netappsantricity_cloud_connectorall versions
netappstorage_automation_storeall versions
netappstoragegridall versions
netappclustered_data_ontapall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2018-1303