Bugzilla – Bug 1101688
VUL-1: CVE-2018-8011: apache2: mod_md DoS
Last modified: 2021-01-12 12:15:07 UTC
CVE-2018-8011 Description: By specially crafting HTTP requests, the mod_md challenge handler would dereference a NULL pointer and cause the child process to segfault. This could be used to DoS the server Mitigation: All httpd users should upgrade to 2.4.34 or later. Credit: The issue was discovered by Daniel Caminada Judging from our changes file SLE 15 only References: https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2018-8011 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-8011 http://seclists.org/oss-sec/2018/q3/40
We do not enable mod_md build. For 15/apache2, I will add update-patch to 1.1.15 in case we will enable it later.
Nevertheless, we are not affected anywhere.
thanks
Package submitted: 15/apache2.
SUSE-SU-2018:2424-1: An update that fixes two vulnerabilities is now available. Category: security (moderate) Bug References: 1101688,1101689 CVE References: CVE-2018-1333,CVE-2018-8011 Sources used: SUSE Linux Enterprise Module for Server Applications 15 (src): apache2-2.4.33-3.3.1
openSUSE-SU-2018:2433-1: An update that fixes two vulnerabilities is now available. Category: security (moderate) Bug References: 1101688,1101689 CVE References: CVE-2018-1333,CVE-2018-8011 Sources used: openSUSE Leap 15.0 (src): apache2-2.4.33-lp150.2.3.1