CVE-2018-1301

All FrameworksApache HTTPDCWE-OtherCVE-2018-1301

CVE-2018-1301

State: PUBLISHED · Published: 2018-03-26 · Updated: 2024-09-16 · Assigner: apache
Description
A specially crafted request could have crashed the Apache HTTP Server prior to version 2.4.30, due to an out of bound access after a size limit is reached by reading the HTTP header. This vulnerability is considered very hard if not impossible to trigger in non-debug mode (both log and build level), so it is classified as low risk for common server usage.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2018/1xxx/CVE-2018-1301.json