Description
By specially crafting HTTP/2 requests, workers would be allocated 60 seconds longer than necessary, leading to worker exhaustion and a denial of service. Fixed in Apache HTTP Server 2.4.34 (Affected 2.4.18-2.4.30,2.4.33).
Published: 2018-06-18
Score: 7.5 High
EPSS: 22.3% Moderate
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Ubuntu USN Ubuntu USN USN-3783-1 Apache HTTP Server vulnerabilities
References
Link Providers
http://www.securitytracker.com/id/1041402 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2018:3558 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2019:0366 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2019:0367 cve-icon cve-icon
https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2018-1333 cve-icon cve-icon cve-icon
https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/r06f0d87ebb6d59ed8379633f36f72f5b1f79cadfda72ede0830b42cf%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/r15f9aa4427581a1aecb4063f1b4b983511ae1c9935e2a0a6876dad3c%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/r76142b8c5119df2178be7c2dba88fde552eedeec37ea993dfce68d1d%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/rd2fb621142e7fa187cfe12d7137bf66e7234abcbbcd800074c84a538%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/re473305a65b4db888e3556e4dae10c2a04ee89dcff2e26ecdbd860a9%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2018-1333 cve-icon
https://security.netapp.com/advisory/ntap-20180926-0007/ cve-icon cve-icon
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03909en_us cve-icon cve-icon
https://usn.ubuntu.com/3783-1/ cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2018-1333 cve-icon
https://www.tenable.com/security/tns-2019-09 cve-icon cve-icon
History

No history.

Subscriptions

Apache Http Server
Canonical Ubuntu Linux
Netapp Cloud Backup Storage Automation Store
Redhat Enterprise Linux Jboss Core Services Rhel Software Collections
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2024-09-17T04:09:37.340Z

Reserved: 2017-12-07T00:00:00.000Z

Link: CVE-2018-1333

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-06-18T18:29:00.257

Modified: 2024-11-21T03:59:38.603

Link: CVE-2018-1333

cve-icon Redhat

Severity : Moderate

Publid Date: 2018-07-18T00:00:00Z

Links: CVE-2018-1333 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses