Lucene search

K
osvGoogleOSV:DLA-284-1
HistoryJul 28, 2015 - 12:00 a.m.

apache2 - security update

2015-07-2800:00:00
Google
osv.dev
16

0.062 Low

EPSS

Percentile

93.6%

A vulnerability has been found in the Apache HTTP Server.

  • CVE-2015-3183
    Apache HTTP Server did not properly parse chunk headers, which
    allowed remote attackers to conduct HTTP request smuggling via a
    crafted request. This flaw relates to mishandling of large
    chunk-size values and invalid chunk-extension characters in
    modules/http/http_filters.c.

For the squeeze distribution, these issues have been fixed in version
2.2.16-6+squeeze15 of apache2.

We recommend you to upgrade your apache2 packages.