CVE-2018-1000168
nghttp2: Null pointer dereference when too large ALTSVC frame is received
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
nghttp2 version >= 1.10.0 and nghttp2 <= v1.31.0 contains an Improper Input Validation CWE-20 vulnerability in ALTSVC frame handling that can result in segmentation fault leading to denial of service. This attack appears to be exploitable via network client. This vulnerability appears to have been fixed in >= 1.31.1.
nghttp2 hasta la versión 1.10.0 y nghttp2 en versiones 1.31.0 y anteriores contienen una vulnerabilidad de validación incorrecta de entradas (CWE-20) en la gestión de tramas ALTSVC que puede resultar en un fallo de segmentación, lo que provoca una denegación de servicio (DoS). Este ataque parece ser explotable mediante un cliente de red. La vulnerabilidad parece haber sido solucionada en la versión 1.31.1 y posteriores.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-04-09 CVE Reserved
- 2018-05-08 CVE Published
- 2024-02-21 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
- CWE-476: NULL Pointer Dereference
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/103952 | Broken Link | |
https://lists.debian.org/debian-lts-announce/2021/10/msg00011.html | Mailing List | |
https://nodejs.org/en/blog/vulnerability/june-2018-security-releases | Release Notes |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://access.redhat.com/errata/RHSA-2019:0366 | 2022-08-16 | |
https://access.redhat.com/errata/RHSA-2019:0367 | 2022-08-16 | |
https://nghttp2.org/blog/2018/04/12/nghttp2-v1-31-1 | 2022-08-16 | |
https://access.redhat.com/security/cve/CVE-2018-1000168 | 2019-02-18 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1565035 | 2019-02-18 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Nghttp2 Search vendor "Nghttp2" | Nghttp2 Search vendor "Nghttp2" for product "Nghttp2" | >= 1.10.0 <= 1.31.0 Search vendor "Nghttp2" for product "Nghttp2" and version " >= 1.10.0 <= 1.31.0" | - |
Affected
| ||||||
Nodejs Search vendor "Nodejs" | Node.js Search vendor "Nodejs" for product "Node.js" | >= 6.0.0 <= 6.8.1 Search vendor "Nodejs" for product "Node.js" and version " >= 6.0.0 <= 6.8.1" | - |
Affected
| ||||||
Nodejs Search vendor "Nodejs" | Node.js Search vendor "Nodejs" for product "Node.js" | >= 8.4.0 <= 8.17.0 Search vendor "Nodejs" for product "Node.js" and version " >= 8.4.0 <= 8.17.0" | lts |
Affected
| ||||||
Nodejs Search vendor "Nodejs" | Node.js Search vendor "Nodejs" for product "Node.js" | >= 9.0.0 <= 9.11.2 Search vendor "Nodejs" for product "Node.js" and version " >= 9.0.0 <= 9.11.2" | - |
Affected
| ||||||
Nodejs Search vendor "Nodejs" | Node.js Search vendor "Nodejs" for product "Node.js" | >= 10.0.0 < 10.4.1 Search vendor "Nodejs" for product "Node.js" and version " >= 10.0.0 < 10.4.1" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 9.0 Search vendor "Debian" for product "Debian Linux" and version "9.0" | - |
Affected
|