Lucene search

K
ubuntucveUbuntu.comUB:CVE-2018-1000168
HistoryApr 12, 2018 - 12:00 a.m.

CVE-2018-1000168

2018-04-1200:00:00
ubuntu.com
ubuntu.com
8

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.042 Low

EPSS

Percentile

92.3%

nghttp2 version >= 1.10.0 and nghttp2 <= v1.31.0 contains an Improper Input
Validation CWE-20 vulnerability in ALTSVC frame handling that can result in
segmentation fault leading to denial of service. This attack appears to be
exploitable via network client. This vulnerability appears to have been
fixed in >= 1.31.1.

Notes

Author Note
mdeslaur Affected versions: nghttp2 >= 1.10.0 and nghttp2 <= v1.31.0
OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchnghttp2< 1.30.0-1ubuntu1UNKNOWN

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.042 Low

EPSS

Percentile

92.3%