Debian Security Advisory

DLA-284-1 apache2 -- LTS security update

Date Reported:
28 Jul 2015
Affected Packages:
apache2
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2015-3183.
More information:

A vulnerability has been found in the Apache HTTP Server.

  • CVE-2015-3183

    Apache HTTP Server did not properly parse chunk headers, which allowed remote attackers to conduct HTTP request smuggling via a crafted request. This flaw relates to mishandling of large chunk-size values and invalid chunk-extension characters in modules/http/http_filters.c.

For the squeeze distribution, these issues have been fixed in version 2.2.16-6+squeeze15 of apache2.

We recommend you to upgrade your apache2 packages.