Behrooz_Ice
11-15-2003, 08:02 PM
A remote vulnerability has been discovered in the Apache HTTP server, versions up to 1.3.24 and 2.0 through 2.0.36 for both Windows and *nix. The hole is in routines which deal with invalid requests encoded using chunked encoding, which is enabled by default. A maliciously crafted request could lead to denial of service or possibly a remote exploit. Apache's official advisory has more information. Enjoy IT!
