CVE Database
/

CVE-2014-0227

Back to search

CVE-2014-0227

Published: Feb 16, 2015

Modified: Aug 6, 2024

PUBLISHED

Description

java/org/apache/coyote/http11/filters/ChunkedInputFilter.java in Apache Tomcat 6.x before 6.0.42, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle attempts to continue reading data after an error has occurred, which allows remote attackers to conduct HTTP request smuggling attacks or cause a denial of service (resource consumption) by streaming data with malformed chunked transfer coding.

VendorProductVersions

n/a

n/a

affected
n/a

References

USN-2654-1
vendor-advisory
x_refsource_UBUNTU
RHSA-2015:0765
vendor-advisory
x_refsource_REDHAT
RHSA-2015:0675
vendor-advisory
x_refsource_REDHAT
MDVSA-2015:052
vendor-advisory
x_refsource_MANDRIVA
HPSBUX03341
vendor-advisory
x_refsource_HP
RHSA-2015:0720
vendor-advisory
x_refsource_REDHAT
SSRT102068
vendor-advisory
x_refsource_HP
72717
vdb-entry
x_refsource_BID
RHSA-2015:0991
vendor-advisory
x_refsource_REDHAT
MDVSA-2015:084
vendor-advisory
x_refsource_MANDRIVA
DSA-3530
vendor-advisory
x_refsource_DEBIAN
1032791
vdb-entry
x_refsource_SECTRACK
RHSA-2015:0983
vendor-advisory
x_refsource_REDHAT
SSRT102066
vendor-advisory
x_refsource_HP
MDVSA-2015:053
vendor-advisory
x_refsource_MANDRIVA
FEDORA-2015-2109
vendor-advisory
x_refsource_FEDORA
USN-2655-1
vendor-advisory
x_refsource_UBUNTU
HPSBUX03337
vendor-advisory
x_refsource_HP
DSA-3447
vendor-advisory
x_refsource_DEBIAN

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now