CVE-2018-17189: Medium severity Apache HTTP Server vulnerability
A flaw was found in HTTP/2 (modhttp2) connections in Apache HTTP Server httpd 2.4.17 to 2.4.37. A DoS can be triggered by sending request bodies in a slow loris way to plain resources, the h2 stream for that request unnecessarily occupied a server thread cleaning up that incoming data.
References: https://seclists.org/oss-sec/2019/q1/80 https://httpd.apache.org/security/vulnerabilities24.html
Other sources
In Apache HTTP server versions 2.4.37 and prior, by sending request bodies in a slow loris way to plain resources, the h2 stream for that request unnecessarily occupied a server thread cleaning up that incoming data. This affects only HTTP/2 (modhttp2) connections.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/jbcs-httpd24-aprto a version that resolves this vulnerability.Fixed in 0:1.6.3-63.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-apr-utilto a version that resolves this vulnerability.Fixed in 0:1.6.1-48.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-brotlito a version that resolves this vulnerability.Fixed in 0:1.0.6-7.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-curlto a version that resolves this vulnerability.Fixed in 0:7.64.1-14.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-httpdto a version that resolves this vulnerability.Fixed in 0:2.4.37-33.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-janssonto a version that resolves this vulnerability.Fixed in 0:2.11-20.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-nghttp2to a version that resolves this vulnerability.Fixed in 0:1.39.2-4.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-opensslto a version that resolves this vulnerability.Fixed in 1:1.1.1-25.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-aprto a version that resolves this vulnerability.Fixed in 0:1.6.3-63.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-apr-utilto a version that resolves this vulnerability.Fixed in 0:1.6.1-48.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-brotlito a version that resolves this vulnerability.Fixed in 0:1.0.6-7.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-curlto a version that resolves this vulnerability.Fixed in 0:7.64.1-14.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-httpdto a version that resolves this vulnerability.Fixed in 0:2.4.37-33.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-janssonto a version that resolves this vulnerability.Fixed in 0:2.11-20.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-nghttp2to a version that resolves this vulnerability.Fixed in 0:1.39.2-4.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-opensslto a version that resolves this vulnerability.Fixed in 1:1.1.1-25.jbcs.el7 - Upgrade
Upgrade
redhat/httpd24to a version that resolves this vulnerability.Fixed in 0:1.1-19.el6 - Upgrade
Upgrade
redhat/httpd24-httpdto a version that resolves this vulnerability.Fixed in 0:2.4.34-15.el6 - Upgrade
Upgrade
redhat/httpd24-nghttp2to a version that resolves this vulnerability.Fixed in 0:1.7.1-8.el6 - Upgrade
Upgrade
redhat/httpd24to a version that resolves this vulnerability.Fixed in 0:1.1-19.el7 - Upgrade
Upgrade
redhat/httpd24-httpdto a version that resolves this vulnerability.Fixed in 0:2.4.34-15.el7 - Upgrade
Upgrade
redhat/httpd24-nghttp2to a version that resolves this vulnerability.Fixed in 0:1.7.1-8.el7 - Upgrade
Upgrade
debian/apache2to a version that resolves this vulnerability.Fixed in 2.4.38-1Fixed in 2.4.25-3+deb9u7 - Upgrade
Upgrade
redhat/httpdto a version that resolves this vulnerability.Fixed in 2.4.38 - Upgrade
Upgrade
debian/apache2to a version that resolves this vulnerability.Fixed in 2.4.62-1~deb11u1Fixed in 2.4.67-1~deb11u3Fixed in 2.4.68-1~deb12u1Fixed in 2.4.67-1~deb12u3Fixed in 2.4.68-1~deb13u1Fixed in 2.4.67-1~deb13u3Fixed in 2.4.68-1 - Upgrade
Upgrade
Apache HTTP Server httpd (mod_http2)to a version that resolves this vulnerability.Fixed in 2.4.38
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2018-17189?
CVE-2018-17189 is classified as a DoS (Denial of Service) vulnerability.
How do I fix CVE-2018-17189?
To fix CVE-2018-17189, upgrade to version 2.4.38 or later of the Apache HTTP Server.
Which Apache HTTP Server versions are affected by CVE-2018-17189?
CVE-2018-17189 affects Apache HTTP Server versions 2.4.17 to 2.4.37.
What happens if my server is vulnerable to CVE-2018-17189?
If your server is vulnerable to CVE-2018-17189, it can be subjected to resource exhaustion due to slow loris attacks.
Is CVE-2018-17189 related to HTTP/2 connections?
Yes, CVE-2018-17189 specifically affects HTTP/2 connections in Apache HTTP Server.