vulnerability

CentOS Linux: CVE-2018-1301: Moderate: httpd security, bug fix, and enhancement update (CESA-2020:1121)

Severity
4
CVSS
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
Published
Mar 26, 2018
Added
Apr 1, 2020
Modified
May 25, 2023

Description

A specially crafted request could have crashed the Apache HTTP Server prior to version 2.4.30, due to an out of bound access after a size limit is reached by reading the HTTP header. This vulnerability is considered very hard if not impossible to trigger in non-debug mode (both log and build level), so it is classified as low risk for common server usage.

Solutions

centos-upgrade-httpdcentos-upgrade-httpd-debuginfocentos-upgrade-httpd-develcentos-upgrade-httpd-manualcentos-upgrade-httpd-toolscentos-upgrade-mod_ldapcentos-upgrade-mod_proxy_htmlcentos-upgrade-mod_sessioncentos-upgrade-mod_ssl
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.