Summary
The remote host is missing an update to the system as announced in the referenced advisory.
Solution
Update your system with the appropriate patches or software upgrades.
http://www.watchfire.com/resources/HTTP-Request-Smuggling.pdf http://www.vuxml.org/freebsd/651996e0-fe07-11d9-8329-000e0c2e438a.html
Insight
The following packages are affected:
apache
apache+ipv6
apache_fp
apache+ssl
apache+mod_perl
apache+mod_ssl
apache+mod_ssl+ipv6
ru-apache
ru-apache+mod_ssl
CVE-2005-2088
Apache 2.0.45 and 1.3.29, when acting as an HTTP proxy, allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a 'Transfer-Encoding: chunked' header and a Content-Length header, which causes Apache to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka 'HTTP Request Smuggling.'
Severity
Classification
-
CVE CVE-2005-2088 -
CVSS Base Score: 4.3
AV:N/AC:M/Au:N/C:N/I:P/A:N
Related Vulnerabilities