ALPINE-CVE-2018-1302

    Dashboard / Vulnerabilities / ALPINE-CVE-2018-1302

    ALPINE-CVE-2018-1302

    Published: 26 Mar 2018Last Modified: 9 Jun 2026
    Upstream:

    Summary:

    Details: When an HTTP/2 stream was destroyed after being handled, the Apache HTTP Server prior to version 2.4.30 could have written a NULL pointer potentially to an already freed memory. The memory pools maintained by the server make this vulnerability hard to trigger in usual configurations, the reporter and the team could not reproduce it outside debug builds, so it is classified as low risk.

    Affected packages

    Package

    Name: apache2

    Purl: pkg:apk/alpine/apache2?arch=source

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -2.4.33-r0

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    ALPINE-CVE-2018-1302 | CVE-DB