CVE-2018-1302
5.9
MEDIUM
CVSS 3.1
EPSS 13.4%
描述
When an HTTP/2 stream was destroyed after being handled, the Apache HTTP Server prior to version 2.4.30 could have written a NULL pointer potentially to an already freed memory. The memory pools maintained by the server make this vulnerability hard to trigger in usual configurations, the reporter and the team could not reproduce it outside debug builds, so it is classified as low risk.
如何修補 CVE-2018-1302
要修補 CVE-2018-1302,請將受影響套件升級到下列已修補版本。
- —升級至 2.4.33-r0 或更新版本
- —升級至 2.4.33-1 或更新版本
CVE-2018-1302 正在被利用嗎?
中等 — EPSS 為 13.4%,可持續追蹤但非最高優先。
受影響套件(2)
- from 0, < 2.4.33-r0
- from 0, < 2.4.33-1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.9 | CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H |