CVE-2018-1302
Publication date 26 March 2018
Last updated 25 August 2025
Ubuntu priority
Cvss 3 Severity Score
Description
When an HTTP/2 stream was destroyed after being handled, the Apache HTTP Server prior to version 2.4.30 could have written a NULL pointer potentially to an already freed memory. The memory pools maintained by the server make this vulnerability hard to trigger in usual configurations, the reporter and the team could not reproduce it outside debug builds, so it is classified as low risk.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| apache2 | 18.04 LTS bionic |
Fixed 2.4.29-1ubuntu4.4
|
| 16.04 LTS xenial |
Not affected
|
|
| 14.04 LTS trusty |
Not affected
|
Notes
mdeslaur
artful and older don't enable http2 in the build. this needs to be fixed by backporting the whole http2 module from a more-recent apache2
Patch details
| Package | Patch details |
|---|---|
| apache2 |
|
Severity score breakdown
| Parameter | Value |
|---|---|
| Base score |
|
| Attack vector | Network |
| Attack complexity | High |
| Privileges required | None |
| User interaction | None |
| Scope | Unchanged |
| Confidentiality | None |
| Integrity impact | None |
| Availability impact | High |
| Vector | CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H |
References
Related Ubuntu Security Notices (USN)
- USN-3783-1
- Apache HTTP Server vulnerabilities
- 3 October 2018