CVE-2018-8011
mod_md, DoS via Coredumps on specially crafted requests
Record summary
CVE-2018-8011 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
By specially crafting HTTP requests, the mod_md challenge handler would dereference a NULL pointer and cause the child process to segfault. This could be used to DoS the server. Fixed in Apache HTTP Server 2.4.34 (Affected 2.4.33).
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Feb 22, 2022 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
HTTP ServerBrowse Apache / HTTP Server | VulnCheck | Version data not supplied | |
Apache HTTP ServerBrowse Apache Software Foundation / Apache HTTP Server | CVE List | Fixed in Apache HTTP Server 2.4.34 (Affected 2.4.33) | affected |
Nuclei templates
1ProjectDiscoveryHIGHApache HTTP Server - NULL Pointer DereferenceCVSS 7.5
By specially crafting HTTP requests, the mod_md challenge handler would dereference a NULL pointer and cause the child process to segfault. This could be used to DoS the server. Fixed in Apache HTTP Server 2.4.34 (Affected 2.4.33)
Impact
Attackers can cause server crashes leading to denial of service, disrupting service availability.
Remediation
Update to version 2.4.34 or later.
Source: ProjectDiscovery