CVE-2002-0392
Apache 1.3 through 1.3.24, and Apache 2.0 through 2.0.36, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a chunk-encoded HTTP request that causes Apache to use an incorrect size.
- Affected products
- Apache, Apache Http Server
- Apache Http Server
- ≤ 1.3.24, 2.0.36
- Fix
- Available
- CVSS 2.0
- 7.5 HIGH
- EPSS
- 95.0% (100th percentile)
- NVD status
- Modified
- Published
- 2003-04-02
CVE-2002-0392 at NVD
10 known exploits for CVE-2002-0392
Proof-of-concept code and exploit modules indexed by Sploitus
Apache (Windows x86) - Chunked Encoding (Metasploit)
Apache Win32 Chunked Encoding
Apache Win32 Chunked Encoding
Apache chunked encoding buffer overflow
Apache chunked encoding buffer overflow
Apache chunked encoding buffer overflow
Apache chunked encoding buffer overflow
Immunity Canvas: APACHECHUNK_WIN32
Apache 1.x/2.0.x - Chunked-Encoding Memory Corruption (1)
Apache 1.x/2.0.x - Chunked-Encoding Memory Corruption (2)