Back

LOW

httpd: HTTP request smuggling attack against chunked request parser

Published Jul 20, 2015

Description

The chunked transfer coding implementation in the Apache HTTP Server before 2.4.14 does not properly parse chunk headers, which allows remote attackers to conduct HTTP request smuggling attacks via a crafted request, related to mishandling of large chunk-size values and invalid chunk-extension characters in modules/http/http_filters.c.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (57)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jul 20, 2015
Updated Aug 6, 2024
Reserved Apr 10, 2015
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jul 15, 2015