CVE-2002-2272
Tomcat 4.0 through 4.1.12, using mod_jk 1.2.1 module on Apache 1.3 through 1.3.27, allows remote attackers to cause a denial of service (desynchronized communications) via an HTTP GET request with a Transfer-Encoding chunked field with invalid values.
- Affected products
- Apache, Apache Tomcat, Mod Jk
- Apache Http Server
- = 1.3, 1.3.0, 1.3.1, 1.3.2, 1.3.10, 1.3.11, 1.3.12, 1.3.13, 1.3.14, 1.3.15, 1.3.16, 1.3.17, 1.3.18, 1.3.19, 1.3.20, 1.3.22, 1.3.23, 1.3.24, 1.3.25, 1.3.26, 1.3.27
- Apache Tomcat
- = 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.5, 4.0.6, 4.1.0, 4.1.1, 4.1.2, 4.1.3, 4.1.9, 4.1.10, 4.1.12
- Fix
- Available
- CVSS 2.0
- 7.8 HIGH
- EPSS
- 9.7% (95th percentile)
- Weakness
- CWE-119
- NVD status
- Modified
- Published
- 2007-10-18
CVE-2002-2272 at NVD
1 known exploit for CVE-2002-2272
Proof-of-concept code and exploit modules indexed by Sploitus