First published: Mon Jun 18 2018(Updated: )
Apache httpd before version 2.4.34 has a vulnerability in the handling of specially crafted HTTP/2 requests, causing workers to be allocated 60 seconds longer than necessary, leading to worker exhaustion and a denial of service. This issue only affects servers that have configured and enabled HTTP/2 support, which is not the default External References: <a href="https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2018-1333">https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2018-1333</a>
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/httpd | <2.4.34 | 2.4.34 |
Apache HTTP server | >=2.4.18<=2.4.30 | |
Apache HTTP server | =2.4.33 | |
Redhat Jboss Core Services | =1.0 | |
Redhat Enterprise Linux | =6.0 | |
Redhat Enterprise Linux | =7.0 | |
Canonical Ubuntu Linux | =18.04 | |
Netapp Cloud Backup | ||
Netapp Storage Automation Store | ||
All of | ||
Redhat Jboss Core Services | =1.0 | |
Any of | ||
Redhat Enterprise Linux | =6.0 | |
Redhat Enterprise Linux | =7.0 | |
debian/apache2 | 2.4.62-1~deb11u1 2.4.61-1~deb11u1 2.4.62-1~deb12u1 2.4.61-1~deb12u1 2.4.62-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1333 is a vulnerability that allows for worker exhaustion and denial of service by crafting specially-crafted HTTP/2 requests in Apache HTTP Server.
CVE-2018-1333 has a severity rating of 7.5 (high).
Apache HTTP Server versions 2.4.18 to 2.4.30 and version 2.4.33 are affected by CVE-2018-1333.
CVE-2018-1333 can be fixed by upgrading to Apache HTTP Server version 2.4.34.
More information about CVE-2018-1333 can be found at the following references: [Link 1](https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2018-1333), [Link 2](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1605049), [Link 3](https://httpd.apache.org/docs/2.4/mod/mod_http2.html).