connection.c in Cherokee web server before 0.4.6 allows remote attackers to cause a denial of service via an HTTP POST request without a Content-Length header field.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Cherokee_httpd | Cherokee | 0.1 (including) | 0.1 (including) |
Cherokee_httpd | Cherokee | 0.1.5 (including) | 0.1.5 (including) |
Cherokee_httpd | Cherokee | 0.1.6 (including) | 0.1.6 (including) |
Cherokee_httpd | Cherokee | 0.2 (including) | 0.2 (including) |
Cherokee_httpd | Cherokee | 0.2.5 (including) | 0.2.5 (including) |
Cherokee_httpd | Cherokee | 0.2.6 (including) | 0.2.6 (including) |
Cherokee_httpd | Cherokee | 0.2.7 (including) | 0.2.7 (including) |
Cherokee_httpd | Cherokee | 0.4.6 (including) | 0.4.6 (including) |