Back

MEDIUM

tomcat: information leak vulnerability in the handling of 'Transfer-Encoding' header

Published Jul 13, 2010

Description

Apache Tomcat 5.5.0 through 5.5.29, 6.0.0 through 6.0.27, and 7.0.0 beta does not properly handle an invalid Transfer-Encoding header, which allows remote attackers to cause a denial of service (application outage) or obtain sensitive information via a crafted header that interferes with "recycling of a buffer."

Affected products

Remediation

No remediation recorded yet.

Metrics

References (75)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jul 13, 2010
Updated Aug 7, 2024
Reserved Jun 9, 2010
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Jul 8, 2010
GHSA-CXG2-49RQ-8GCR