UBUNTU-CVE-2015-3183
Dashboard / Vulnerabilities / UBUNTU-CVE-2015-3183
UBUNTU-CVE-2015-3183
Summary:
Details: The chunked transfer coding implementation in the Apache HTTP Server before 2.4.14 does not properly parse chunk headers, which allows remote attackers to conduct HTTP request smuggling attacks via a crafted request, related to mishandling of large chunk-size values and invalid chunk-extension characters in modules/http/http_filters.c.
References: https://ubuntu.com/security/CVE-2015-3183, https://www.apache.org/dist/httpd/Announcement2.4.txt, https://www.apache.org/dist/httpd/CHANGES_2.4.16, https://ubuntu.com/security/notices/USN-2686-1, https://www.cve.org/CVERecord?id=CVE-2015-3183
Affected packages
Package
Name: apache2
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
