UBUNTU-CVE-2018-1302

    Dashboard / Vulnerabilities / UBUNTU-CVE-2018-1302

    UBUNTU-CVE-2018-1302

    Published: 26 Mar 2018Last Modified: 22 Apr 2026
    Upstream:
    Aliases:

    Summary:

    Details: When an HTTP/2 stream was destroyed after being handled, the Apache HTTP Server prior to version 2.4.30 could have written a NULL pointer potentially to an already freed memory. The memory pools maintained by the server make this vulnerability hard to trigger in usual configurations, the reporter and the team could not reproduce it outside debug builds, so it is classified as low risk.

    Affected packages

    Package

    Name: apache2

    Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=bionic

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -2.4.29-1ubuntu4.4

    Affected versions

    2.4.27-2ubuntu3
    2.4.29-1ubuntu1
    2.4.29-1ubuntu2
    2.4.29-1ubuntu3
    2.4.29-1ubuntu4
    2.4.29-1ubuntu4.1
    2.4.29-1ubuntu4.2
    2.4.29-1ubuntu4.3

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High