CVE-2018-1000168
Summary
| CVE | CVE-2018-1000168 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-05-08 15:29:00 UTC |
| Updated | 2022-08-16 13:01:00 UTC |
| Description | nghttp2 version >= 1.10.0 and nghttp2 <= v1.31.0 contains an Improper Input Validation CWE-20 vulnerability in ALTSVC frame handling that can result in segmentation fault leading to denial of service. This attack appears to be exploitable via network client. This vulnerability appears to have been fixed in >= 1.31.1. |
Risk And Classification
Problem Types: CWE-20 | CWE-476
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Application | Nghttp2 | Nghttp2 | All | All | All | All |
| Application | Nodejs | Node.js | All | All | All | All |
| Application | Nodejs | Node.js | All | All | All | All |
| Application | Nodejs | Node.js | All | All | All | All |
| Application | Nodejs | Node.js | All | All | All | All |
| Application | Nodejs | Node.js | All | All | All | All |
| Application | Nodejs | Node.js | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Red Hat Customer Portal | REDHAT | access.redhat.com | Third Party Advisory |
| Red Hat Customer Portal | REDHAT | access.redhat.com | Third Party Advisory |
| nghttp2 CVE-2018-1000168 Remote Denial of Service Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| June 2018 Security Releases | Node.js | CONFIRM | nodejs.org | Third Party Advisory |
| Nghttp2 v1.31.1 - nghttp2.org | CONFIRM | nghttp2.org | Vendor Advisory |
| [SECURITY] [DLA 2786-1] nghttp2 security update | MLIST | lists.debian.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 174904 SUSE Enterprise Linux Security Update for nghttp2 (SUSE-SU-2021:0932-1)
- 178839 Debian Security Update for nghttp2 (DLA 2786-1)
- 500449 Alpine Linux Security Update for nodejs
- 504215 Alpine Linux Security Update for nodejs
- 900064 CBL-Mariner Linux Security Update for nodejs 8.11.4
- 902895 Common Base Linux Mariner (CBL-Mariner) Security Update for nodejs (4289)