DescriptionApache HTTP Request Parsing Whitespace Defects
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
apache2 (PTS)wheezy2.2.22-13+deb7u6vulnerable
wheezy (security)2.2.22-13+deb7u7vulnerable
jessie (security)2.4.10-10+deb8u5vulnerable
stretch, sid2.4.25-3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs

The fix is not fully backwards compatible so upstream have
created a new option to control this behaviour. This means that
if this is fixed the security advisory need to mention this.
The fix is invasive and should require some extra testing before reaching
stable and old-stable.
Affects: 2.2.0 to 2.4.23.
Fixed in 2.4.25.
For 2.2 preparation is done in

Search for package or bug name: Reporting problems