Vulnerability record · CVE-2002-0392 · published 3 July 2002
CVE-2002-0392: Apache HTTP Server chunked encoding flaw allows DoS and possible code execution
Apache · Http Server
Apache HTTP Server versions 1.3 through 1.3.24 and 2.0 through 2.0.36 mishandle the size value in chunk-encoded HTTP requests, causing the server to use an incorrect size. This can crash the server and, per the description, possibly allow execution of arbitrary code. The record does not specify the exact root cause or the affected code path.
Description
Apache 1.3 through 1.3.24, and Apache 2.0 through 2.0.36, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a chunk-encoded HTTP request that causes Apache to use an incorrect size.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityThe flaw is remotely reachable without authentication and can cause denial of service with possible code execution, and the very high EPSS score signals likely exploitation activity despite the absence of KEV listing.
What it is
Apache HTTP Server versions 1.3 through 1.3.24 and 2.0 through 2.0.36 mishandle the size value in chunk-encoded HTTP requests, causing the server to use an incorrect size. This can crash the server and, per the description, possibly allow execution of arbitrary code. The record does not specify the exact root cause or the affected code path.
Impact
A remote attacker can cause a denial of service against the web server and may be able to execute arbitrary code in the server's context. The record does not confirm which of the two outcomes is reliably achievable.
Attack surface
Reachable over the network by sending a crafted chunk-encoded HTTP request to the server; no authentication or user interaction is required per the CVSS vector AV:N/AC:L/Au:N.
Exploitation
Not listed in CISA KEV and no ransomware association is recorded, but EPSS is very high (0.95027, 99.858th percentile), indicating strong predicted exploitation activity; reference tags are advisory and patch links, with no exploit tag present.
What to do
- Upgrade to a fixed Apache HTTP Server release; the vendor bulletin and CERT advisory CA-2002-17 reference the patches for the 1.3 and 2.0 branches.
- Apply the distribution security updates (Debian DSA-131/132/133 and equivalent vendor errata) if the packaged Apache cannot be replaced immediately.
- If patching is delayed, restrict or filter chunked transfer-encoding requests at a reverse proxy or WAF and limit exposure of the server to untrusted networks.
- Monitor the server for crashes and abnormal child process termination, and treat repeated crashes as possible exploitation attempts.
Detection
- Inspect HTTP request logs for malformed or unusual Transfer-Encoding: chunked requests, especially those with inconsistent chunk size values.
- Alert on Apache child process crashes, core dumps, or unexpected restarts correlated with inbound HTTP traffic.
- Hunt for shell or command execution spawned by the Apache process user, which would indicate successful code execution rather than a simple crash.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2002-0392 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2002-0392), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.