UBUNTU-CVE-2018-8022

Source
https://ubuntu.com/security/CVE-2018-8022
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-8022.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2018-8022
Upstream
Withdrawn
2025-07-18T16:44:32Z
Published
2018-08-29T13:29:00Z
Modified
2025-07-16T07:39:04.541023Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

A carefully crafted invalid TLS handshake can cause Apache Traffic Server (ATS) to segfault. This affects version 6.2.2. To resolve this issue users running 6.2.2 should upgrade to 6.2.3 or later versions.

References

Affected packages

Ubuntu:18.04:LTS / trafficserver

Package

Name
trafficserver
Purl
pkg:deb/ubuntu/trafficserver@7.1.2+ds-3?arch=source&distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.1.2+ds-3

Affected versions

7.*
7.0.0-5
7.1.2+ds-2
7.1.2+ds-2build1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "trafficserver",
            "binary_version": "7.1.2+ds-3"
        },
        {
            "binary_name": "trafficserver-dbgsym",
            "binary_version": "7.1.2+ds-3"
        },
        {
            "binary_name": "trafficserver-dev",
            "binary_version": "7.1.2+ds-3"
        },
        {
            "binary_name": "trafficserver-experimental-plugins",
            "binary_version": "7.1.2+ds-3"
        },
        {
            "binary_name": "trafficserver-experimental-plugins-dbgsym",
            "binary_version": "7.1.2+ds-3"
        }
    ],
    "availability": "No subscription required"
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-8022.json"