Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 662894 (CVE-2018-1333, CVE-2018-8011)

Summary: <www-servers/apache-2.4.34: multiple vulnerabilities (CVE-2018-{1333,8011})
Product: Gentoo Security Reporter: GLSAMaker/CVETool Bot <glsamaker>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: minor CC: polynomial-c
Priority: Normal Flags: stable-bot: sanity-check+
Version: unspecified   
Hardware: All   
OS: Linux   
URL: https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2018-1333
Whiteboard: B3 [noglsa cve]
Package list:
app-admin/apache-tools-2.4.34 www-servers/apache-2.4.34-r2
Runtime testing required: ---

Description GLSAMaker/CVETool Bot gentoo-dev 2018-08-05 23:21:58 UTC
CVE-2018-8011 (https://nvd.nist.gov/vuln/detail/CVE-2018-8011):
  By specially crafting HTTP requests, the mod_md challenge handler would
  dereference a NULL pointer and cause the child process to segfault. This
  could be used to DoS the server. Fixed in Apache HTTP Server 2.4.34
  (Affected 2.4.33).
Comment 1 Thomas Deutschmann (RETIRED) gentoo-dev 2018-08-05 23:23:53 UTC
@ Maintainer(s): Can we start stabilization of =www-servers/apache-2.4.34-r1?
Comment 2 Thomas Deutschmann (RETIRED) gentoo-dev 2018-08-06 00:05:12 UTC
low: DoS for HTTP/2 connections by crafted requests (CVE-2018-1333)

    By specially crafting HTTP/2 requests, workers would be allocated 60 seconds longer than necessary, leading to worker exhaustion and a denial of service.

    This issue only affects servers that have configured and enabled HTTP/2 support, which is not the default

    Acknowledgements: The issue was discovered by Craig Young of Tripwire VERT.
Comment 3 Thomas Deutschmann (RETIRED) gentoo-dev 2018-08-06 22:21:14 UTC
x86 stable
Comment 4 Agostino Sarubbo gentoo-dev 2018-08-07 08:50:46 UTC
amd64 stable
Comment 5 Sergei Trofimovich (RETIRED) gentoo-dev 2018-08-11 19:03:34 UTC
ia64 stable
Comment 6 Sergei Trofimovich (RETIRED) gentoo-dev 2018-08-11 19:06:13 UTC
ppc64 stable
Comment 7 Markus Meier gentoo-dev 2018-08-22 04:57:55 UTC
arm stable
Comment 8 Tobias Klausmann (RETIRED) gentoo-dev 2018-09-13 19:24:05 UTC
Stable on alpha.
Comment 9 Matt Turner gentoo-dev 2018-09-16 19:52:58 UTC
ppc stable

all arches done
Comment 10 Christopher Díaz Riveros (RETIRED) gentoo-dev Security 2018-12-09 13:59:14 UTC
GLSA Vote: no
Comment 11 Christopher Díaz Riveros (RETIRED) gentoo-dev Security 2018-12-09 14:27:55 UTC
@Maintainers please cleanup older versions.

Thank you!
Comment 12 Aaron Bauman (RETIRED) gentoo-dev 2019-03-10 21:05:54 UTC
@maintainer, is cleanup on hold?
Comment 13 Aaron Bauman (RETIRED) gentoo-dev 2019-03-28 02:17:39 UTC
cleanup will happen in bug #676064