CVE-2018-1333

medium
Published — · Modified —
CVSS v3
CVSS v4 NEW
not yet in upstream
VIR risk
5.5

Description

By specially crafting HTTP/2 requests, workers would be allocated 60 seconds longer than necessary, leading to worker exhaustion and a denial of service. Fixed in Apache HTTP Server 2.4.34 (Affected 2.4.18-2.4.30,2.4.33).

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker · View original ↗ · DFSG

CVE-2018-1333 NameCVE-2018-1333 DescriptionBy specially crafting HTTP/2 requests, workers would be allocated 60 seconds longer than necessary, leading to worker exhaustion and a denial of service. Fixed in Apache HTTP Server 2.4.34 (Affected 2.4.18-2.4.30,2.4.33). SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub…

CVE-2018-1333

NameCVE-2018-1333
DescriptionBy specially crafting HTTP/2 requests, workers would be allocated 60 seconds longer than necessary, leading to worker exhaustion and a denial of service. Fixed in Apache HTTP Server 2.4.34 (Affected 2.4.18-2.4.30,2.4.33).
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs904106

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
apache2 (PTS)bullseye2.4.62-1~deb11u1fixed
bullseye (security)2.4.67-1~deb11u1fixed
bookworm, bookworm (security)2.4.67-1~deb12u2fixed
trixie (security), trixie2.4.67-1~deb13u2fixed
forky2.4.67-1fixed
sid2.4.67-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
apache2sourcejessie(not affected)
apache2sourcestretch2.4.25-3+deb9u6
apache2source(unstable)2.4.34-1904106

Notes

[jessie] - apache2 <not-affected> (Vulnerable code not present)
Affects 2.4.18-2.4.33
HTTP/2 support introduced in 2.4.17
https://www.openwall.com/lists/oss-security/2018/07/18/1
https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2018-1333

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
[jessie] - apache2 <not-affected> (Vulnerable code not present)Affects 2.4.18-2.4.33HTTP/2 support introduced in 2.4.17https://www.openwall.com/lists/oss-security/2018/07/18/1https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2018-1333

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
Affected
arch Arch Fixed 1 release
VersionStatusFixed in
Fixed 2.4.34-1
debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 2.4.34-1
sid Fixed 2.4.34-1
forky Fixed 2.4.34-1
bullseye Fixed 2.4.34-1
bookworm Fixed 2.4.34-1

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.