CVE-2018-1318
moderate-risk
Published 2018-08-29
Adding method ACLs in remap.config can cause a segfault when the user makes a carefully crafted request. This affects versions Apache Traffic Server (ATS) 6.0.0 to 6.2.2 and 7.0.0 to 7.1.3. To resolve this issue users running 6.x should upgrade to 6.2.3 or later versions and 7.x users should upgrade to 7.1.4 or later versions.
Do I need to act?
!
14.6% chance of exploitation in next 30 days
EPSS score — higher than 85% of all CVEs
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.5/10
High
NETWORK
/ LOW complexity
Affected Products (2)
References (8)
Third Party Advisory
http://www.securityfocus.com/bid/105176
Third Party Advisory
https://github.com/apache/trafficserver/pull/3195
Third Party Advisory
https://www.debian.org/security/2018/dsa-4282
Third Party Advisory
http://www.securityfocus.com/bid/105176
Third Party Advisory
https://github.com/apache/trafficserver/pull/3195
Third Party Advisory
https://www.debian.org/security/2018/dsa-4282
45
/ 100
moderate-risk
Severity
26/34 · High
Exploitability
12/34 · Low
Exposure
7/34 · Low