CVE Vulnerabilities

CVE-2015-3183

Published: Jul 20, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
2.6 MODERATE
AV:N/AC:H/Au:N/C:N/I:N/A:P
RedHat/V3
3.7 MODERATE
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The chunked transfer coding implementation in the Apache HTTP Server before 2.4.14 does not properly parse chunk headers, which allows remote attackers to conduct HTTP request smuggling attacks via a crafted request, related to mishandling of large chunk-size values and invalid chunk-extension characters in modules/http/http_filters.c.

Affected Software

NameVendorStart VersionEnd Version
Http_serverApache2.2.0 (including)2.2.31 (excluding)
Http_serverApache2.4.0 (including)2.4.16 (excluding)
Red Hat Enterprise Linux 6RedHathttpd-0:2.2.15-47.el6_7*
Red Hat Enterprise Linux 7RedHathttpd-0:2.4.6-31.el7_1.1*
Red Hat JBoss Enterprise Application Platform 6.4RedHat*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHathornetq-native-0:2.3.25-4.SP11_redhat_1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHathttpd-0:2.2.26-54.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjbcs-httpd24-0:1-3.jbcs.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatjbcs-httpd24-openssl-1:1.0.2h-4.jbcs.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatmod_cluster-native-0:1.2.13-3.Final_redhat_2.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHatmod_jk-0:1.2.41-2.redhat_4.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6RedHattomcat-native-0:1.1.34-5.redhat_1.ep6.el6*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHathornetq-native-0:2.3.25-4.SP11_redhat_1.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHathttpd22-0:2.2.26-56.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjbcs-httpd24-0:1-3.jbcs.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatjbcs-httpd24-openssl-1:1.0.2h-4.jbcs.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatmod_cluster-native-0:1.2.13-3.Final_redhat_2.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHatmod_jk-0:1.2.41-2.redhat_4.ep6.el7*
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7RedHattomcat-native-0:1.1.34-5.redhat_1.ep6.el7*
Red Hat JBoss Enterprise Web Server 2 for RHEL 5RedHathttpd-0:2.2.26-41.ep6.el5*
Red Hat JBoss Enterprise Web Server 2 for RHEL 5RedHatmod_cluster-native-0:1.2.9-6.Final_redhat_2.ep6.el5*
Red Hat JBoss Enterprise Web Server 2 for RHEL 6RedHathttpd-0:2.2.26-41.ep6.el6*
Red Hat JBoss Enterprise Web Server 2 for RHEL 6RedHatmod_cluster-native-0:1.2.9-6.Final_redhat_2.ep6.el6*
Red Hat JBoss Enterprise Web Server 2 for RHEL 7RedHathttpd22-0:2.2.26-42.ep6.el7*
Red Hat JBoss Enterprise Web Server 2 for RHEL 7RedHatmod_cluster-native-0:1.2.9-6.Final_redhat_2.ep6.el7*
Red Hat JBoss Web Server 2.1RedHathttpd*
Red Hat JBoss Web Server 3.0RedHat*
Red Hat JBoss Web Server 3 for RHEL 6RedHatapache-commons-collections-eap6-0:3.2.1-18.redhat_7.1.ep6.el6*
Red Hat JBoss Web Server 3 for RHEL 6RedHathttpd24-0:2.4.6-59.ep7.el6*
Red Hat JBoss Web Server 3 for RHEL 6RedHatmod_bmx-0:0.9.5-7.GA.ep7.el6*
Red Hat JBoss Web Server 3 for RHEL 6RedHatmod_cluster-native-0:1.3.1-6.Final_redhat_2.ep7.el6*
Red Hat JBoss Web Server 3 for RHEL 6RedHattomcat7-0:7.0.59-42_patch_01.ep7.el6*
Red Hat JBoss Web Server 3 for RHEL 6RedHattomcat8-0:8.0.18-52_patch_01.ep7.el6*
Red Hat JBoss Web Server 3 for RHEL 6RedHattomcat-vault-0:1.0.8-4.Final_redhat_4.1.ep7.el6*
Red Hat JBoss Web Server 3 for RHEL 7RedHatapache-commons-collections-eap6-0:3.2.1-18.redhat_7.1.ep6.el7*
Red Hat JBoss Web Server 3 for RHEL 7RedHathttpd24-0:2.4.6-59.ep7.el7*
Red Hat JBoss Web Server 3 for RHEL 7RedHatmod_bmx-0:0.9.5-7.GA.ep7.el7*
Red Hat JBoss Web Server 3 for RHEL 7RedHatmod_cluster-native-0:1.3.1-6.Final_redhat_2.ep7.el7*
Red Hat JBoss Web Server 3 for RHEL 7RedHattomcat7-0:7.0.59-42_patch_01.ep7.el7*
Red Hat JBoss Web Server 3 for RHEL 7RedHattomcat8-0:8.0.18-52_patch_01.ep7.el7*
Red Hat JBoss Web Server 3 for RHEL 7RedHattomcat-vault-0:1.0.8-4.Final_redhat_4.1.ep7.el7*
Red Hat Software Collections for Red Hat Enterprise Linux 6RedHathttpd24-httpd-0:2.4.12-4.el6.2*
Red Hat Software Collections for Red Hat Enterprise Linux 6.5 EUSRedHathttpd24-httpd-0:2.4.12-4.el6.2*
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUSRedHathttpd24-httpd-0:2.4.12-4.el6.2*
Red Hat Software Collections for Red Hat Enterprise Linux 7RedHathttpd24-httpd-0:2.4.12-6.el7.1*
Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUSRedHathttpd24-httpd-0:2.4.12-6.el7.1*
Apache2Ubuntudevel*
Apache2Ubuntuesm-infra-legacy/trusty*
Apache2Ubuntuprecise*
Apache2Ubuntutrusty*
Apache2Ubuntutrusty/esm*
Apache2Ubuntuupstream*
Apache2Ubuntuutopic*
Apache2Ubuntuvivid*

References