CVE Database
/

CVE-2018-1302

Back to search

CVE-2018-1302

Published: Mar 26, 2018

Modified: Sep 17, 2024

PUBLISHED

Description

When an HTTP/2 stream was destroyed after being handled, the Apache HTTP Server prior to version 2.4.30 could have written a NULL pointer potentially to an already freed memory. The memory pools maintained by the server make this vulnerability hard to trigger in usual configurations, the reporter and the team could not reproduce it outside debug builds, so it is classified as low risk.

VendorProductVersions

Apache Software Foundation

Apache HTTP Server

affected
2.4.17 to 2.4.29

References

RHSA-2019:0367
vendor-advisory
x_refsource_REDHAT
103528
vdb-entry
x_refsource_BID
1040567
vdb-entry
x_refsource_SECTRACK
USN-3783-1
vendor-advisory
x_refsource_UBUNTU
RHSA-2019:0366
vendor-advisory
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now