Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-3183

Опубликовано: 15 июл. 2015
Источник: redhat
CVSS3: 3.7
CVSS2: 2.6
EPSS Средний

Описание

The chunked transfer coding implementation in the Apache HTTP Server before 2.4.14 does not properly parse chunk headers, which allows remote attackers to conduct HTTP request smuggling attacks via a crafted request, related to mishandling of large chunk-size values and invalid chunk-extension characters in modules/http/http_filters.c.

Multiple flaws were found in the way httpd parsed HTTP requests and responses using chunked transfer encoding. A remote attacker could use these flaws to create a specially crafted request, which httpd would decode differently from an HTTP proxy software in front of it, possibly leading to HTTP request smuggling attacks.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
CloudForms Management Engine 5httpdAffected
Red Hat Directory Server 8httpdWill not fix
Red Hat Enterprise Linux 4httpdWill not fix
Red Hat Enterprise Linux 5httpdWill not fix
Red Hat JBoss Enterprise Web Server 1httpdWill not fix
Red Hat Enterprise Linux 6httpdFixedRHSA-2015:166824.08.2015
Red Hat Enterprise Linux 7httpdFixedRHSA-2015:166724.08.2015
Red Hat JBoss Enterprise Application Platform 6.4FixedRHSA-2016:205612.10.2016
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6hornetq-nativeFixedRHSA-2016:205512.10.2016
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6httpdFixedRHSA-2016:205512.10.2016

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-172
https://bugzilla.redhat.com/show_bug.cgi?id=1243887httpd: HTTP request smuggling attack against chunked request parser

EPSS

Процентиль: 97%
0.38976
Средний

3.7 Low

CVSS3

2.6 Low

CVSS2

Связанные уязвимости

ubuntu
около 10 лет назад

The chunked transfer coding implementation in the Apache HTTP Server before 2.4.14 does not properly parse chunk headers, which allows remote attackers to conduct HTTP request smuggling attacks via a crafted request, related to mishandling of large chunk-size values and invalid chunk-extension characters in modules/http/http_filters.c.

nvd
около 10 лет назад

The chunked transfer coding implementation in the Apache HTTP Server before 2.4.14 does not properly parse chunk headers, which allows remote attackers to conduct HTTP request smuggling attacks via a crafted request, related to mishandling of large chunk-size values and invalid chunk-extension characters in modules/http/http_filters.c.

debian
около 10 лет назад

The chunked transfer coding implementation in the Apache HTTP Server b ...

suse-cvrf
почти 10 лет назад

Security update for apache2

suse-cvrf
почти 10 лет назад

Security update for apache2

EPSS

Процентиль: 97%
0.38976
Средний

3.7 Low

CVSS3

2.6 Low

CVSS2