Back to search
CVE-2014-0227
Published: Feb 16, 2015
Modified: Aug 6, 2024
PUBLISHED
Description
java/org/apache/coyote/http11/filters/ChunkedInputFilter.java in Apache Tomcat 6.x before 6.0.42, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle attempts to continue reading data after an error has occurred, which allows remote attackers to conduct HTTP request smuggling attacks or cause a denial of service (resource consumption) by streaming data with malformed chunked transfer coding.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html
x_refsource_CONFIRM
USN-2654-1
vendor-advisory
x_refsource_UBUNTU
RHSA-2015:0765
vendor-advisory
x_refsource_REDHAT
RHSA-2015:0675
vendor-advisory
x_refsource_REDHAT
MDVSA-2015:052
vendor-advisory
x_refsource_MANDRIVA
HPSBUX03341
vendor-advisory
x_refsource_HP
RHSA-2015:0720
vendor-advisory
x_refsource_REDHAT
SSRT102068
vendor-advisory
x_refsource_HP
72717
vdb-entry
x_refsource_BID
RHSA-2015:0991
vendor-advisory
x_refsource_REDHAT
MDVSA-2015:084
vendor-advisory
x_refsource_MANDRIVA
DSA-3530
vendor-advisory
x_refsource_DEBIAN
1032791
vdb-entry
x_refsource_SECTRACK
http://tomcat.apache.org/security-7.html
x_refsource_CONFIRM
RHSA-2015:0983
vendor-advisory
x_refsource_REDHAT
SSRT102066
vendor-advisory
x_refsource_HP
MDVSA-2015:053
vendor-advisory
x_refsource_MANDRIVA
http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html
x_refsource_CONFIRM
FEDORA-2015-2109
vendor-advisory
x_refsource_FEDORA
http://tomcat.apache.org/security-8.html
x_refsource_CONFIRM
https://bugzilla.redhat.com/show_bug.cgi?id=1109196
x_refsource_CONFIRM
https://source.jboss.org/changelog/JBossWeb?cs=2455
x_refsource_CONFIRM
20150209 [SECURITY] CVE-2014-0227 Apache Tomcat Request Smuggling
mailing-list
x_refsource_BUGTRAQ
http://advisories.mageia.org/MGASA-2015-0081.html
x_refsource_CONFIRM
http://tomcat.apache.org/security-6.html
x_refsource_CONFIRM
USN-2655-1
vendor-advisory
x_refsource_UBUNTU
http://svn.apache.org/viewvc?view=revision&revision=1600984
x_refsource_CONFIRM
HPSBUX03337
vendor-advisory
x_refsource_HP
DSA-3447
vendor-advisory
x_refsource_DEBIAN
[tomcat-dev] 20190319 svn commit: r1855831 [23/30] - in /tomcat/site/trunk: ./ docs/ xdocs/
mailing-list
x_refsource_MLIST
[tomcat-dev] 20190325 svn commit: r1856174 [21/29] - in /tomcat/site/trunk: docs/ xdocs/ xdocs/stylesheets/
mailing-list
x_refsource_MLIST
[tomcat-dev] 20190413 svn commit: r1857494 [15/20] - in /tomcat/site/trunk: ./ docs/ xdocs/
mailing-list
x_refsource_MLIST
[tomcat-dev] 20190415 svn commit: r1857582 [16/22] - in /tomcat/site/trunk: docs/ xdocs/stylesheets/
mailing-list
x_refsource_MLIST
[tomcat-dev] 20200203 svn commit: r1873527 [23/30] - /tomcat/site/trunk/docs/
mailing-list
x_refsource_MLIST
[tomcat-dev] 20200213 svn commit: r1873980 [27/34] - /tomcat/site/trunk/docs/
mailing-list
x_refsource_MLIST
[tomcat-dev] 20200213 svn commit: r1873980 [26/34] - /tomcat/site/trunk/docs/
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now