CVE Vulnerabilities

CVE-2015-3183

Published: Jul 20, 2015 | Modified: Dec 14, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
2.6 MODERATE
AV:N/AC:H/Au:N/C:N/I:N/A:P
RedHat/V3
3.7 MODERATE
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Ubuntu
MEDIUM

The chunked transfer coding implementation in the Apache HTTP Server before 2.4.14 does not properly parse chunk headers, which allows remote attackers to conduct HTTP request smuggling attacks via a crafted request, related to mishandling of large chunk-size values and invalid chunk-extension characters in modules/http/http_filters.c.

Affected Software

Name Vendor Start Version End Version
Http_server Apache 2.2.0 (including) 2.2.31 (excluding)
Http_server Apache 2.4.0 (including) 2.4.16 (excluding)
Apache2 Ubuntu devel *
Apache2 Ubuntu precise *
Apache2 Ubuntu trusty *
Apache2 Ubuntu upstream *
Apache2 Ubuntu utopic *
Apache2 Ubuntu vivid *
Red Hat Enterprise Linux 6 RedHat httpd-0:2.2.15-47.el6_7 *
Red Hat Enterprise Linux 7 RedHat httpd-0:2.4.6-31.ael7b_1.1 *
Red Hat JBoss Enterprise Application Platform 6.4 RedHat *
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 RedHat hornetq-native-0:2.3.25-4.SP11_redhat_1.ep6.el6 *
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 RedHat httpd-0:2.2.26-54.ep6.el6 *
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 RedHat jbcs-httpd24-0:1-3.jbcs.el6 *
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 RedHat jbcs-httpd24-openssl-1:1.0.2h-4.jbcs.el6 *
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 RedHat mod_cluster-native-0:1.2.13-3.Final_redhat_2.ep6.el6 *
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 RedHat mod_jk-0:1.2.41-2.redhat_4.ep6.el6 *
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6 RedHat tomcat-native-0:1.1.34-5.redhat_1.ep6.el6 *
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7 RedHat hornetq-native-0:2.3.25-4.SP11_redhat_1.ep6.el7 *
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7 RedHat httpd22-0:2.2.26-56.ep6.el7 *
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7 RedHat jbcs-httpd24-0:1-3.jbcs.el7 *
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7 RedHat jbcs-httpd24-openssl-1:1.0.2h-4.jbcs.el7 *
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7 RedHat mod_cluster-native-0:1.2.13-3.Final_redhat_2.ep6.el7 *
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7 RedHat mod_jk-0:1.2.41-2.redhat_4.ep6.el7 *
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 7 RedHat tomcat-native-0:1.1.34-5.redhat_1.ep6.el7 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 5 RedHat httpd-0:2.2.26-41.ep6.el5 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 5 RedHat mod_cluster-native-0:1.2.9-6.Final_redhat_2.ep6.el5 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 6 RedHat httpd-0:2.2.26-41.ep6.el6 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 6 RedHat mod_cluster-native-0:1.2.9-6.Final_redhat_2.ep6.el6 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 7 RedHat httpd22-0:2.2.26-42.ep6.el7 *
Red Hat JBoss Enterprise Web Server 2 for RHEL 7 RedHat mod_cluster-native-0:1.2.9-6.Final_redhat_2.ep6.el7 *
Red Hat JBoss Web Server 2.1 RedHat httpd *
Red Hat JBoss Web Server 3.0 RedHat *
Red Hat JBoss Web Server 3 for RHEL 6 RedHat apache-commons-collections-eap6-0:3.2.1-18.redhat_7.1.ep6.el6 *
Red Hat JBoss Web Server 3 for RHEL 6 RedHat httpd24-0:2.4.6-59.ep7.el6 *
Red Hat JBoss Web Server 3 for RHEL 6 RedHat mod_bmx-0:0.9.5-7.GA.ep7.el6 *
Red Hat JBoss Web Server 3 for RHEL 6 RedHat mod_cluster-native-0:1.3.1-6.Final_redhat_2.ep7.el6 *
Red Hat JBoss Web Server 3 for RHEL 6 RedHat tomcat7-0:7.0.59-42_patch_01.ep7.el6 *
Red Hat JBoss Web Server 3 for RHEL 6 RedHat tomcat8-0:8.0.18-52_patch_01.ep7.el6 *
Red Hat JBoss Web Server 3 for RHEL 6 RedHat tomcat-vault-0:1.0.8-4.Final_redhat_4.1.ep7.el6 *
Red Hat JBoss Web Server 3 for RHEL 7 RedHat apache-commons-collections-eap6-0:3.2.1-18.redhat_7.1.ep6.el7 *
Red Hat JBoss Web Server 3 for RHEL 7 RedHat httpd24-0:2.4.6-59.ep7.el7 *
Red Hat JBoss Web Server 3 for RHEL 7 RedHat mod_bmx-0:0.9.5-7.GA.ep7.el7 *
Red Hat JBoss Web Server 3 for RHEL 7 RedHat mod_cluster-native-0:1.3.1-6.Final_redhat_2.ep7.el7 *
Red Hat JBoss Web Server 3 for RHEL 7 RedHat tomcat7-0:7.0.59-42_patch_01.ep7.el7 *
Red Hat JBoss Web Server 3 for RHEL 7 RedHat tomcat8-0:8.0.18-52_patch_01.ep7.el7 *
Red Hat JBoss Web Server 3 for RHEL 7 RedHat tomcat-vault-0:1.0.8-4.Final_redhat_4.1.ep7.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 6 RedHat httpd24-httpd-0:2.4.12-4.el6.2 *
Red Hat Software Collections for Red Hat Enterprise Linux 6.5 EUS RedHat httpd24-httpd-0:2.4.12-4.el6.2 *
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS RedHat httpd24-httpd-0:2.4.12-4.el6.2 *
Red Hat Software Collections for Red Hat Enterprise Linux 7 RedHat httpd24-httpd-0:2.4.12-6.el7.1 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUS RedHat httpd24-httpd-0:2.4.12-6.el7.1 *

References