Bug 1086820 - (CVE-2018-1302) VUL-0: CVE-2018-1302: apache2: CVE-2018-1302: Possible write of after free on HTTP/2 stream shutdown
(CVE-2018-1302)
VUL-0: CVE-2018-1302: apache2: CVE-2018-1302: Possible write of after free on...
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Normal
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/202610/
CVSSv3:SUSE:CVE-2018-1302:5.6:(AV:N/A...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2018-03-26 09:38 UTC by Karol Babioch
Modified: 2018-10-18 16:43 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Karol Babioch 2018-03-26 09:38:37 UTC
CVE-2018-1302: Possible write of after free on HTTP/2 stream shutdown

Severity: Low

Vendor: The Apache Software Foundation

Versions Affected:
httpd 2.4.17 to 2.4.29

Description:
When an HTTP/2 stream was destroyed after being handled, the Apache HTTP Server
prior to version 2.4.30 could have written a NULL pointer potentially to an
already freed memory. The memory pools maintained by the server make this
vulnerabilty hard to trigger in usual configurations, the reporter and the team
could not reproduce it outside debug builds, so it is classified as low risk.

Mitigation:
All httpd users should upgrade to 2.4.30 or later.

Credit:
The issue was discovered by Robert Swiecki, bug found by honggfuzz

References:
https://httpd.apache.org/security/vulnerabilities_24.html
Comment 1 Karol Babioch 2018-03-26 09:53:28 UTC
HTTP2 support was added in 2.4.17, so only SUSE:SLE-12-SP2:Update is affected.
Comment 3 Karol Babioch 2018-03-27 15:11:57 UTC
Yeah, this commit is the right one. We don't need all of the comment changes in the headers, though ;).
Comment 4 Petr Gajdos 2018-03-27 15:38:31 UTC
I will consider to update mod_http2 to 1.10.16 anyway.
Comment 8 Petr Gajdos 2018-04-04 10:41:35 UTC
Submitted for: 12sp2
I believe all fixed.
Comment 10 Swamp Workflow Management 2018-04-05 19:10:44 UTC
SUSE-SU-2018:0879-1: An update that solves 6 vulnerabilities and has one errata is now available.

Category: security (important)
Bug References: 1057406,1086774,1086775,1086813,1086814,1086817,1086820
CVE References: CVE-2017-15710,CVE-2017-15715,CVE-2018-1283,CVE-2018-1301,CVE-2018-1303,CVE-2018-1312
Sources used:
SUSE OpenStack Cloud 6 (src):    apache2-2.4.16-20.16.1
SUSE Linux Enterprise Server for SAP 12-SP1 (src):    apache2-2.4.16-20.16.1
SUSE Linux Enterprise Server 12-SP1-LTSS (src):    apache2-2.4.16-20.16.1
Comment 11 Swamp Workflow Management 2018-04-09 01:08:27 UTC
SUSE-SU-2018:0901-1: An update that solves 6 vulnerabilities and has one errata is now available.

Category: security (important)
Bug References: 1057406,1086774,1086775,1086813,1086814,1086817,1086820
CVE References: CVE-2017-15710,CVE-2017-15715,CVE-2018-1283,CVE-2018-1301,CVE-2018-1303,CVE-2018-1312
Sources used:
SUSE Linux Enterprise Server 12-LTSS (src):    apache2-2.4.10-14.31.1
Comment 12 Swamp Workflow Management 2018-05-07 16:11:01 UTC
SUSE-SU-2018:1161-1: An update that fixes 7 vulnerabilities is now available.

Category: security (moderate)
Bug References: 1086774,1086775,1086813,1086814,1086817,1086820
CVE References: CVE-2017-15710,CVE-2017-15715,CVE-2018-1283,CVE-2018-1301,CVE-2018-1302,CVE-2018-1303,CVE-2018-1312
Sources used:
SUSE OpenStack Cloud 7 (src):    apache2-2.4.23-29.18.2
SUSE Linux Enterprise Software Development Kit 12-SP3 (src):    apache2-2.4.23-29.18.2
SUSE Linux Enterprise Server for SAP 12-SP2 (src):    apache2-2.4.23-29.18.2
SUSE Linux Enterprise Server 12-SP3 (src):    apache2-2.4.23-29.18.2
SUSE Linux Enterprise Server 12-SP2-LTSS (src):    apache2-2.4.23-29.18.2
Comment 13 Swamp Workflow Management 2018-05-09 22:10:11 UTC
openSUSE-SU-2018:1198-1: An update that fixes 7 vulnerabilities is now available.

Category: security (moderate)
Bug References: 1086774,1086775,1086813,1086814,1086817,1086820
CVE References: CVE-2017-15710,CVE-2017-15715,CVE-2018-1283,CVE-2018-1301,CVE-2018-1302,CVE-2018-1303,CVE-2018-1312
Sources used:
openSUSE Leap 42.3 (src):    apache2-2.4.23-22.1
Comment 14 Marcus Meissner 2018-05-11 07:54:07 UTC
released
Comment 15 Swamp Workflow Management 2018-10-18 16:43:09 UTC
SUSE-SU-2018:1161-2: An update that fixes 7 vulnerabilities is now available.

Category: security (moderate)
Bug References: 1086774,1086775,1086813,1086814,1086817,1086820
CVE References: CVE-2017-15710,CVE-2017-15715,CVE-2018-1283,CVE-2018-1301,CVE-2018-1302,CVE-2018-1303,CVE-2018-1312
Sources used:
SUSE Linux Enterprise Server 12-SP2-BCL (src):    apache2-2.4.23-29.18.2