Bug 998145 (CVE-2002-0392) - VUL-0: CVE-2002-0392: apache,apache2: RCE via chunk-encoded HTTP requests
Summary: VUL-0: CVE-2002-0392: apache,apache2: RCE via chunk-encoded HTTP requests
Status: RESOLVED FIXED
Alias: CVE-2002-0392
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P5 - None : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL:
Whiteboard: CVSSv2:NVD:CVE-2002-0392:7.5:(AV:N/A...
Keywords:
Depends on:
Blocks:
 
Reported: 2016-09-09 11:20 UTC by Marcus Meissner
Modified: 2018-10-02 17:52 UTC (History)
0 users

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2016-09-09 11:20:04 UTC
via cve db

Apache 1.3 through 1.3.24, and Apache 2.0 through 2.0.36, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a chunk-encoded HTTP request that causes Apache to use an incorrect size. 

CONFIRM:http://httpd.apache.org/info/security_bulletin_20020617.txt
Comment 1 Marcus Meissner 2016-09-09 11:25:40 UTC
(this bug is opened for historic reasons, we seem not have had one in 2002.)
Comment 2 Marcus Meissner 2016-09-09 13:25:43 UTC
was fixed in 1.3.26 (sles8 times) and 2.0.37 (before sles9 shipment)