5.3

CVE-2018-17189

In Apache HTTP server versions 2.4.37 and prior, by sending request bodies in a slow loris way to plain resources, the h2 stream for that request unnecessarily occupied a server thread cleaning up that incoming data. This affects only HTTP/2 (mod_http2) connections.

Data is provided by the National Vulnerability Database (NVD)
ApacheHTTP Server Version2.4.17
ApacheHTTP Server Version2.4.18
ApacheHTTP Server Version2.4.20
ApacheHTTP Server Version2.4.23
ApacheHTTP Server Version2.4.25
ApacheHTTP Server Version2.4.26
ApacheHTTP Server Version2.4.27
ApacheHTTP Server Version2.4.28
ApacheHTTP Server Version2.4.29
ApacheHTTP Server Version2.4.30
ApacheHTTP Server Version2.4.33
ApacheHTTP Server Version2.4.34
ApacheHTTP Server Version2.4.35
ApacheHTTP Server Version2.4.37
FedoraprojectFedora Version28
FedoraprojectFedora Version29
DebianDebian Linux Version9.0
OracleHospitality Guest Access Version4.2.0
OracleHospitality Guest Access Version4.2.1
CanonicalUbuntu Linux Version14.04 SwEditionesm
CanonicalUbuntu Linux Version16.04 SwEditionesm
CanonicalUbuntu Linux Version18.04 SwEditionlts
CanonicalUbuntu Linux Version18.10
RedhatJboss Core Services Version1.0
   RedhatEnterprise Linux Version6.0
   RedhatEnterprise Linux Version7.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 6.15% 0.904
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.

http://www.securityfocus.com/bid/106685
Third Party Advisory
VDB Entry
https://seclists.org/bugtraq/2019/Apr/5
Third Party Advisory
Mailing List
Issue Tracking
https://usn.ubuntu.com/3937-1/
Third Party Advisory