CVE-2010-2227
medium · 6.4Apache Tomcat 5.5.0 through 5.5.29, 6.0.0 through 6.0.27, and 7.0.0 beta does not properly handle an invalid Transfer-Encoding header, which allows remote attackers to cause a denial of service (application outage) or obtain sensitive information via a crafted header that interferes with "recycling of a buffer."
6.4
CVSS
54.8%
EPSS (exploit prob.)
99th
EPSS percentile
2010-07-13
Published
AV:N/AC:L/Au:N/C:P/I:N/A:P
Weaknesses
CWE-119
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| apache | tomcat | 5.5.0 |
| apache | tomcat | 5.5.1 |
| apache | tomcat | 5.5.2 |
| apache | tomcat | 5.5.3 |
| apache | tomcat | 5.5.4 |
| apache | tomcat | 5.5.5 |
| apache | tomcat | 5.5.6 |
| apache | tomcat | 5.5.7 |
| apache | tomcat | 5.5.8 |
| apache | tomcat | 5.5.9 |
| apache | tomcat | 5.5.10 |
| apache | tomcat | 5.5.11 |
| apache | tomcat | 5.5.12 |
| apache | tomcat | 5.5.13 |
| apache | tomcat | 5.5.14 |
| apache | tomcat | 5.5.15 |
| apache | tomcat | 5.5.16 |
| apache | tomcat | 5.5.17 |
| apache | tomcat | 5.5.18 |
| apache | tomcat | 5.5.19 |
| apache | tomcat | 5.5.20 |
| apache | tomcat | 5.5.21 |
| apache | tomcat | 5.5.22 |
| apache | tomcat | 5.5.23 |
| apache | tomcat | 5.5.24 |
| apache | tomcat | 5.5.25 |
| apache | tomcat | 5.5.26 |
| apache | tomcat | 5.5.27 |
| apache | tomcat | 5.5.28 |
| apache | tomcat | 5.5.29 |
| apache | tomcat | 6.0.0 |
| apache | tomcat | 6.0.1 |
| apache | tomcat | 6.0.2 |
| apache | tomcat | 6.0.3 |
| apache | tomcat | 6.0.4 |
| apache | tomcat | 6.0.5 |
| apache | tomcat | 6.0.6 |
| apache | tomcat | 6.0.7 |
| apache | tomcat | 6.0.8 |
| apache | tomcat | 6.0.9 |
Check a specific version with /api/v1/cve/match.
References
- http://geronimo.apache.org/21x-security-report.html
- http://geronimo.apache.org/22x-security-report.html
- http://lists.apple.com/archives/Security-announce/2011//Oct/msg00003.html
- http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050207.html
- http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050214.html
- http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00006.html
- http://marc.info/?l=bugtraq&m=129070310906557&w=2
- http://marc.info/?l=bugtraq&m=136485229118404&w=2
- http://marc.info/?l=bugtraq&m=139344343412337&w=2
- http://secunia.com/advisories/40813
- http://secunia.com/advisories/41025
- http://secunia.com/advisories/42079
- http://secunia.com/advisories/42368
- http://secunia.com/advisories/42454
- http://secunia.com/advisories/43310
- http://secunia.com/advisories/44183
- http://secunia.com/advisories/57126
- http://securitytracker.com/id?1024180
- http://support.apple.com/kb/HT5002
- http://svn.apache.org/viewvc?view=revision&revision=958911
- http://svn.apache.org/viewvc?view=revision&revision=958977
- http://svn.apache.org/viewvc?view=revision&revision=959428
- http://tomcat.apache.org/security-5.html
- http://tomcat.apache.org/security-6.html
- http://tomcat.apache.org/security-7.html
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2010-2227