Candidate: CVE-2014-0095 PublicDate: 2014-05-31 11:17:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0095 Description: java/org/apache/coyote/ajp/AbstractAjpProcessor.java in Apache Tomcat 8.x before 8.0.4 allows remote attackers to cause a denial of service (thread consumption) by using a "Content-Length: 0" AJP request to trigger a hang in request processing. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_tomcat8: upstream_tomcat8: released (8.0.5-1) lucid_tomcat8: DNE precise_tomcat8: DNE saucy_tomcat8: DNE trusty_tomcat8: DNE trusty/esm_tomcat8: DNE utopic_tomcat8: ignored (reached end-of-life) vivid_tomcat8: ignored (reached end-of-life) vivid/stable-phone-overlay_tomcat8: DNE vivid/ubuntu-core_tomcat8: DNE wily_tomcat8: not-affected (8.0.26-1) devel_tomcat8: not-affected (8.0.32-1ubuntu1)