UBUNTU-CVE-2018-1000168

See a problem?
Source
https://ubuntu.com/security/notices/UBUNTU-CVE-2018-1000168
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-1000168.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2018-1000168
Related
Published
2018-04-12T15:00:00Z
Modified
2018-04-12T15:00:00Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

nghttp2 version >= 1.10.0 and nghttp2 <= v1.31.0 contains an Improper Input Validation CWE-20 vulnerability in ALTSVC frame handling that can result in segmentation fault leading to denial of service. This attack appears to be exploitable via network client. This vulnerability appears to have been fixed in >= 1.31.1.

References

Affected packages

Ubuntu:16.04:LTS / nghttp2

Package

Name
nghttp2
Purl
pkg:deb/ubuntu/nghttp2@1.7.1-1?arch=src?distro=xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.7.1-1

Affected versions

0.*

0.6.7-1

1.*

1.3.4-2
1.4.0-1
1.4.0-2
1.5.0-2
1.6.0-1
1.7.0-1

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "libnghttp2-14-dbgsym": "1.7.1-1",
            "nghttp2": "1.7.1-1",
            "libnghttp2-14": "1.7.1-1",
            "libnghttp2-dev": "1.7.1-1",
            "nghttp2-client-dbgsym": "1.7.1-1",
            "libnghttp2-doc": "1.7.1-1",
            "nghttp2-proxy": "1.7.1-1",
            "nghttp2-server": "1.7.1-1",
            "nghttp2-client": "1.7.1-1",
            "nghttp2-server-dbgsym": "1.7.1-1",
            "nghttp2-proxy-dbgsym": "1.7.1-1"
        }
    ]
}

Ubuntu:18.04:LTS / nghttp2

Package

Name
nghttp2
Purl
pkg:deb/ubuntu/nghttp2@1.30.0-1ubuntu1?arch=src?distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.30.0-1ubuntu1

Affected versions

1.*

1.25.0-1
1.27.0-1
1.28.0-1
1.29.0-1
1.29.0-1build1
1.30.0-1

Ecosystem specific

{
    "availability": "No subscription required",
    "ubuntu_priority": "medium",
    "binaries": [
        {
            "libnghttp2-14-dbgsym": "1.30.0-1ubuntu1",
            "nghttp2": "1.30.0-1ubuntu1",
            "libnghttp2-14": "1.30.0-1ubuntu1",
            "libnghttp2-dev": "1.30.0-1ubuntu1",
            "nghttp2-client-dbgsym": "1.30.0-1ubuntu1",
            "libnghttp2-doc": "1.30.0-1ubuntu1",
            "nghttp2-proxy": "1.30.0-1ubuntu1",
            "nghttp2-server": "1.30.0-1ubuntu1",
            "nghttp2-client": "1.30.0-1ubuntu1",
            "nghttp2-server-dbgsym": "1.30.0-1ubuntu1",
            "nghttp2-proxy-dbgsym": "1.30.0-1ubuntu1"
        }
    ]
}