CVE-2018-1333: DoS for HTTP/2 connections by crafted requests
Apache httpd before version 2.4.34 has a vulnerability in the handling of specially crafted HTTP/2 requests, causing workers to be allocated 60 seconds longer than necessary, leading to worker exhaustion and a denial of service.
This issue only affects servers that have configured and enabled HTTP/2 support, which is not the default
External References:
https://httpd.apache.org/security/vulnerabilities24.html#CVE-2018-1333
Other sources
By specially crafting HTTP/2 requests, workers would be allocated 60 seconds longer than necessary, leading to worker exhaustion and a denial of service. Fixed in Apache HTTP Server 2.4.34 (Affected 2.4.18-2.4.30,2.4.33).
— Launchpad
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2018-1333?
CVE-2018-1333 is a vulnerability that allows for worker exhaustion and denial of service by crafting specially-crafted HTTP/2 requests in Apache HTTP Server.
How severe is CVE-2018-1333?
CVE-2018-1333 has a severity rating of 7.5 (high).
Which software versions are affected by CVE-2018-1333?
Apache HTTP Server versions 2.4.18 to 2.4.30 and version 2.4.33 are affected by CVE-2018-1333.
How can CVE-2018-1333 be fixed?
CVE-2018-1333 can be fixed by upgrading to Apache HTTP Server version 2.4.34.
Where can I find more information about CVE-2018-1333?
More information about CVE-2018-1333 can be found at the following references: [Link 1](https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2018-1333), [Link 2](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1605049), [Link 3](https://httpd.apache.org/docs/2.4/mod/mod_http2.html).