Debian Security Advisory
DLA-284-1 apache2 -- LTS security update
- Date Reported:
- 28 Jul 2015
- Affected Packages:
- apache2
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2015-3183.
- More information:
-
A vulnerability has been found in the Apache HTTP Server.
- CVE-2015-3183
Apache HTTP Server did not properly parse chunk headers, which allowed remote attackers to conduct HTTP request smuggling via a crafted request. This flaw relates to mishandling of large chunk-size values and invalid chunk-extension characters in modules/http/http_filters.c.
For the squeeze distribution, these issues have been fixed in version 2.2.16-6+squeeze15 of apache2.
We recommend you to upgrade your apache2 packages.
- CVE-2015-3183