Candidate: CVE-2018-8011 PublicDate: 2018-07-18 14:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-8011 http://www.openwall.com/lists/oss-security/2018/07/18/2 https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2018-8011 Description: By specially crafting HTTP requests, the mod_md challenge handler would dereference a NULL pointer and cause the child process to segfault. This could be used to DoS the server. Fixed in Apache HTTP Server 2.4.34 (Affected 2.4.33). Ubuntu-Description: Notes: mdeslaur> only affects 2.4.33 Bugs: Priority: medium Discovered-by: Daniel Caminada Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_apache2: upstream_apache2: released (2.4.34) precise/esm_apache2: not-affected trusty_apache2: not-affected (2.4.7-1ubuntu4.20) trusty/esm_apache2: not-affected (2.4.7-1ubuntu4.20) xenial_apache2: not-affected (2.4.18-2ubuntu3.9) esm-infra/xenial_apache2: not-affected (2.4.18-2ubuntu3.9) artful_apache2: not-affected (2.4.27-2ubuntu4.2) bionic_apache2: not-affected (2.4.29-1ubuntu4.2) devel_apache2: released (2.4.34-1ubuntu1)