cbcvebase.
CVE-2015-3183
published 2015-07-20

CVE-2015-3183: The chunked transfer coding implementation in the Apache HTTP Server before 2.4.14 does not properly parse chunk headers, which allows remote attackers to…

PriorityP347medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
73.33%
99.4th percentile
The chunked transfer coding implementation in the Apache HTTP Server before 2.4.14 does not properly parse chunk headers, which allows remote attackers to conduct HTTP request smuggling attacks via a crafted request, related to mishandling of large chunk-size values and invalid chunk-extension characters in modules/http/http_filters.c.

Affected

5 ranges
VendorProductVersion rangeFixed in
apachehttp_server>= 2.2.0 < 2.2.312.2.31
apachehttp_server>= 2.4.0 < 2.4.162.4.16
appleos_x_server_v5.0.3
appleos_x_yosemite_v10.10.5_and_security_update_2015-006
debianapache2< apache2 2.4.16-1 (bookworm)apache2 2.4.16-1 (bookworm)

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability exists in the chunked transfer coding implementation; look for HTTP requests with crafted chunk headers containing large chunk-size values or invalid chunk-extension characters targeting Apache HTTP Server before 2.4.14.
  • Monitor for HTTP request smuggling patterns in traffic between a reverse proxy and Apache httpd, where the proxy and httpd decode chunked encoding differently due to malformed chunk headers.
  • ·The vulnerable code is specifically located in modules/http/http_filters.c within Apache HTTP Server; patch or upgrade to 2.4.14 or later to remediate.
  • ·Deployments where Apache httpd sits behind an HTTP proxy are at elevated risk, as the smuggling attack relies on differential chunked-encoding parsing between the two components.
  • ·Tenable strongly recommends SecurityCenter be installed on a subnet that is not Internet addressable to reduce exposure to this vulnerability.

CVSS provenance

nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
vendor_ubuntu5.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.