Record summary

CVE-2018-8011 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

By specially crafting HTTP requests, the mod_md challenge handler would dereference a NULL pointer and cause the child process to segfault. This could be used to DoS the server. Fixed in Apache HTTP Server 2.4.34 (Affected 2.4.33).

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Feb 22, 2022 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied
CVE ListFixed in Apache HTTP Server 2.4.34 (Affected 2.4.33)affected

Nuclei templates

1
ProjectDiscoveryHIGHApache HTTP Server - NULL Pointer DereferenceCVSS 7.5

By specially crafting HTTP requests, the mod_md challenge handler would dereference a NULL pointer and cause the child process to segfault. This could be used to DoS the server. Fixed in Apache HTTP Server 2.4.34 (Affected 2.4.33)

Impact

Attackers can cause server crashes leading to denial of service, disrupting service availability.

Remediation

Update to version 2.4.34 or later.

WeaknessesCWE-119
Authorsdaffainfo
Template tagscvecve2018jsapachehttpddosvkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CPE: cpe:2.3:a:apache:http_server:2.4.33:*:*:*:*:*:*:*
Shodan: cpe:"cpe:2.3:a:apache:http_server"

Source: ProjectDiscovery

References

Showing 12 of 15