nghttp2: Null pointer dereference when too large ALTSVC frame is received
Published May 8, 2018
7.5
HIGHCVSS 3.1
EPSS 10.65%
Description
nghttp2 version >= 1.10.0 and nghttp2 <= v1.31.0 contains an Improper Input Validation CWE-20 vulnerability in ALTSVC frame handling that can result in segmentation fault leading to denial of service. This attack appears to be exploitable via network client. This vulnerability appears to have been fixed in >= 1.31.1.
Affected products
No data.
Configuration 2
Configuration 3
- 9.0
No data.
JBoss Core Services on RHEL 6
jbcs-httpd24-0:1-6.jbcs.el6
Fixed · RHSA-2019:0367
JBoss Core Services on RHEL 6
jbcs-httpd24-apache-commons-daemon-jsvc-1:1.1.0-3.redhat_2.jbcs.el6
Fixed · RHSA-2019:0367
JBoss Core Services on RHEL 6
jbcs-httpd24-apr-0:1.6.3-31.jbcs.el6
Fixed · RHSA-2019:0367
JBoss Core Services on RHEL 6
jbcs-httpd24-apr-util-0:1.6.1-24.jbcs.el6
Fixed · RHSA-2019:0367
JBoss Core Services on RHEL 6
jbcs-httpd24-httpd-0:2.4.29-35.jbcs.el6
Fixed · RHSA-2019:0367
JBoss Core Services on RHEL 6
jbcs-httpd24-mod_cluster-native-0:1.3.8-3.Final_redhat_2.jbcs.el6
Fixed · RHSA-2019:0367
JBoss Core Services on RHEL 6
jbcs-httpd24-mod_jk-0:1.2.46-1.redhat_1.jbcs.el6
Fixed · RHSA-2019:0367
JBoss Core Services on RHEL 6
jbcs-httpd24-nghttp2-0:1.29.0-9.jbcs.el6
Fixed · RHSA-2019:0367
JBoss Core Services on RHEL 6
jbcs-httpd24-openssl-1:1.0.2n-14.jbcs.el6
Fixed · RHSA-2019:0367
JBoss Core Services on RHEL 7
jbcs-httpd24-0:1-6.jbcs.el7
Fixed · RHSA-2019:0367
JBoss Core Services on RHEL 7
jbcs-httpd24-apache-commons-daemon-jsvc-1:1.1.0-3.redhat_2.jbcs.el7
Fixed · RHSA-2019:0367
JBoss Core Services on RHEL 7
jbcs-httpd24-apr-0:1.6.3-31.jbcs.el7
Fixed · RHSA-2019:0367
JBoss Core Services on RHEL 7
jbcs-httpd24-apr-util-0:1.6.1-24.jbcs.el7
Fixed · RHSA-2019:0367
JBoss Core Services on RHEL 7
jbcs-httpd24-httpd-0:2.4.29-35.jbcs.el7
Fixed · RHSA-2019:0367
JBoss Core Services on RHEL 7
jbcs-httpd24-mod_cluster-native-0:1.3.8-3.Final_redhat_2.jbcs.el7
Fixed · RHSA-2019:0367
JBoss Core Services on RHEL 7
jbcs-httpd24-mod_jk-0:1.2.46-1.redhat_1.jbcs.el7
Fixed · RHSA-2019:0367
JBoss Core Services on RHEL 7
jbcs-httpd24-nghttp2-0:1.29.0-9.jbcs.el7
Fixed · RHSA-2019:0367
JBoss Core Services on RHEL 7
jbcs-httpd24-openssl-1:1.0.2n-14.jbcs.el7
Fixed · RHSA-2019:0367
Red Hat JBoss Core Services
n/a
Fixed · RHSA-2019:0366
Red Hat Enterprise Linux 8
nghttp2
Not affected
Red Hat Software Collections
httpd24-nghttp2
Not affected
Red Hat Software Collections
rh-nodejs8-nodejs
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| JBoss Core Services on RHEL 6 | jbcs-httpd24-0:1-6.jbcs.el6 | Fixed | RHSA-2019:0367 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-apache-commons-daemon-jsvc-1:1.1.0-3.redhat_2.jbcs.el6 | Fixed | RHSA-2019:0367 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-apr-0:1.6.3-31.jbcs.el6 | Fixed | RHSA-2019:0367 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-apr-util-0:1.6.1-24.jbcs.el6 | Fixed | RHSA-2019:0367 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-httpd-0:2.4.29-35.jbcs.el6 | Fixed | RHSA-2019:0367 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-mod_cluster-native-0:1.3.8-3.Final_redhat_2.jbcs.el6 | Fixed | RHSA-2019:0367 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-mod_jk-0:1.2.46-1.redhat_1.jbcs.el6 | Fixed | RHSA-2019:0367 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-nghttp2-0:1.29.0-9.jbcs.el6 | Fixed | RHSA-2019:0367 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-openssl-1:1.0.2n-14.jbcs.el6 | Fixed | RHSA-2019:0367 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-0:1-6.jbcs.el7 | Fixed | RHSA-2019:0367 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-apache-commons-daemon-jsvc-1:1.1.0-3.redhat_2.jbcs.el7 | Fixed | RHSA-2019:0367 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-apr-0:1.6.3-31.jbcs.el7 | Fixed | RHSA-2019:0367 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-apr-util-0:1.6.1-24.jbcs.el7 | Fixed | RHSA-2019:0367 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-httpd-0:2.4.29-35.jbcs.el7 | Fixed | RHSA-2019:0367 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-mod_cluster-native-0:1.3.8-3.Final_redhat_2.jbcs.el7 | Fixed | RHSA-2019:0367 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-mod_jk-0:1.2.46-1.redhat_1.jbcs.el7 | Fixed | RHSA-2019:0367 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-nghttp2-0:1.29.0-9.jbcs.el7 | Fixed | RHSA-2019:0367 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-openssl-1:1.0.2n-14.jbcs.el7 | Fixed | RHSA-2019:0367 |
| Red Hat JBoss Core Services | n/a | Fixed | RHSA-2019:0366 |
| Red Hat Enterprise Linux 8 | nghttp2 | Not affected | n/a |
| Red Hat Software Collections | httpd24-nghttp2 | Not affected | n/a |
| Red Hat Software Collections | rh-nodejs8-nodejs | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (10)
- http://www.securityfocus.com/bid/103952 vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2019:0366 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:0367 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2018-1000168 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1565035 Issue Tracking
- https://lists.debian.org/debian-lts-announce/2021/10/msg00011.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://nghttp2.org/blog/2018/04/12/nghttp2-v1-31-1/ x_refsource_CONFIRMVendor Advisory
- https://nodejs.org/en/blog/vulnerability/june-2018-security-releases/ x_refsource_CONFIRMRelease NotesThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-1000168
- https://www.cve.org/CVERecord?id=CVE-2018-1000168
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/103952 | vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry | |
| https://access.redhat.com/errata/RHSA-2019:0366 | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| https://access.redhat.com/errata/RHSA-2019:0367 | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2018-1000168 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1565035 | Issue Tracking | |
| https://lists.debian.org/debian-lts-announce/2021/10/msg00011.html | mailing-listx_refsource_MLISTMailing ListThird Party Advisory | |
| https://nghttp2.org/blog/2018/04/12/nghttp2-v1-31-1/ | x_refsource_CONFIRMVendor Advisory | |
| https://nodejs.org/en/blog/vulnerability/june-2018-security-releases/ | x_refsource_CONFIRMRelease NotesThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-1000168 | ||
| https://www.cve.org/CVERecord?id=CVE-2018-1000168 |
Change history (0)
No recorded changes yet.