VDB

ALPINE-CVE-2018-1302

ALPINE-CVE-2018-1302 PUBLISHED CVSS 5.900000095367432 MEDIUM

When an HTTP/2 stream was destroyed after being handled, the Apache HTTP Server prior to version 2.4.30 could have written a NULL pointer potentially to an already freed memory. The memory pools maintained by the server make this vulnerability hard to trigger in usual configurations, the reporter and the team could not reproduce it outside debug builds, so it is classified as low risk.

Risk Scores

CVSS v3.0
5.900000095367432
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Alpine:v3.7apache20, 2.4.9-r1, 2.4.9-r0
Alpine:v3.4apache22.2.21-r2, 0, 2.2.16-r0
Alpine:v3.14apache22.4.6-r0, 2.4.9-r1, 2.4.9-r0
Alpine:v3.19apache22.4.25-r0, 2.4.9-r1, 2.4.9-r0
Alpine:v3.16apache22.4.12-r0, 2.4.9-r1, 2.4.9-r0
Alpine:v3.10apache22.4.9-r1, 2.4.9-r0, 2.4.7-r0
Alpine:v3.8apache22.4.17-r0, 0, 2.2.16-r0
Alpine:v3.23apache22.4.9-r1, 2.4.9-r0, 2.4.7-r0
Alpine:v3.6apache22.4.17-r4, 2.4.9-r1, 2.4.9-r0
Alpine:v3.22apache22.4.12-r0, 0, 2.2.16-r0
Alpine:v3.9apache22.4.28-r0, 2.4.27-r2, 2.4.27-r1
Alpine:v3.21apache22.2.21-r2, 0, 2.2.16-r0
Alpine:v3.17apache22.4.9-r1, 2.2.16-r0, 2.2.16-r1
Alpine:v3.20apache22.4.10-r0, 0, 2.4.9-r1
Alpine:v3.18apache22.2.20-r0, 2.4.9-r1, 2.4.9-r0
Alpine:v3.13apache20, 2.2.22-r0, 2.2.22-r1
Alpine:v3.5apache22.4.9-r1, 2.4.9-r0, 2.4.7-r0
Alpine:v3.15apache22.4.17-r1, 2.2.22-r0, 2.2.22-r1
Alpine:v3.12apache22.4.6-r2, 2.2.21-r2, 2.2.21-r1
Alpine:v3.11apache22.4.9-r1, 2.2.16-r0, 2.2.16-r1

Timeline

  • Mar 26, 2018 CVE Published
  • Dec 3, 2025 CVE Updated
  • Apr 30, 2026 Distribution Patch
Open in Interactive Console →
$ Console Community · 100/wk Open console ›