Bugzilla – Bug 998145
VUL-0: CVE-2002-0392: apache,apache2: RCE via chunk-encoded HTTP requests
Last modified: 2018-10-02 17:52:22 UTC
via cve db Apache 1.3 through 1.3.24, and Apache 2.0 through 2.0.36, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a chunk-encoded HTTP request that causes Apache to use an incorrect size. CONFIRM:http://httpd.apache.org/info/security_bulletin_20020617.txt
(this bug is opened for historic reasons, we seem not have had one in 2002.)
was fixed in 1.3.26 (sles8 times) and 2.0.37 (before sles9 shipment)