CVE-2018-8011

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
18/07/2018
Last modified:
07/11/2023

Description

By specially crafting HTTP requests, the mod_md challenge handler would dereference a NULL pointer and cause the child process to segfault. This could be used to DoS the server. Fixed in Apache HTTP Server 2.4.34 (Affected 2.4.33).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:http_server:2.4.33:*:*:*:*:*:*:*
cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools