---
title: "CVE-2014-0230\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2014-0230?format=md
keywords: index, follow
---

# CVE-2014-0230

Publication date 7 June 2015

Last updated 24 July 2024

---

Ubuntu priority

**Low**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.55, and 8.x before 8.0.9
does not properly handle cases where an HTTP response occurs before
finishing the reading of an entire request body, which allows remote
attackers to cause a denial of service (thread consumption) via a series of
aborted upload attempts.

### From the Ubuntu Security Team

It was discovered that Tomcat incorrectly handled HTTP responses occurring
before the entire request body was finished being read. A remote attacker
could possibly use this issue to cause a limited denial of service.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2014-0230?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| tomcat6 | 18.04 LTS bionic | Not in release |
| 17.10 artful | Not in release |
| 17.04 zesty | Not in release |
| 16.10 yakkety | Not in release |
| 16.04 LTS xenial | Fixed 6.0.45+dfsg-1 |
| 15.10 wily | Ignored end of life |
| 15.04 vivid | Ignored end of life |
| 14.10 utopic | Ignored end of life |
| 14.04 LTS trusty | Fixed 6.0.39-1ubuntu0.1 |
| 12.04 LTS precise | Fixed 6.0.35-1ubuntu3.6 |
| 10.04 LTS lucid | Ignored end of life |
| tomcat7 | 18.04 LTS bionic | Not affected |
| 17.10 artful | Not affected |
| 17.04 zesty | Not affected |
| 16.10 yakkety | Not affected |
| 16.04 LTS xenial | Not affected |
| 15.10 wily | Not affected |
| 15.04 vivid | Not affected |
| 14.10 utopic | Not affected |
| 14.04 LTS trusty | Fixed 7.0.52-1ubuntu0.3 |
| 12.04 LTS precise | Ignored end of life |
| 10.04 LTS lucid | Not in release |
| tomcat8 | 18.04 LTS bionic | Not affected |
| 17.10 artful | Not affected |
| 17.04 zesty | Not affected |
| 16.10 yakkety | Not affected |
| 16.04 LTS xenial | Not affected |
| 15.10 wily | Not affected |
| 15.04 vivid | Not affected |
| 14.10 utopic | Not affected |
| 14.04 LTS trusty | Not in release |
| 12.04 LTS precise | Not in release |
| 10.04 LTS lucid | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2014-0230?format=md#patch-details)

## Notes

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

ASF says this is a low severity issue that, unlike the original
description, can't cause memory consumption, only a limited
denial of service.
http://mail-archives.apache.org/mod\_mbox/tomcat-announce/201505.mbox/%3C554949D1.8030904%40apache.org%3E

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| tomcat6 | * Upstream:   <https://svn.apache.org/viewvc?view=revision&revision=1659537> |
| tomcat7 | * Upstream:   <https://svn.apache.org/viewvc?view=revision&revision=1603781> |

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0230)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2014-0230)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2014-0230)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2014-0230)

### Related Ubuntu Security Notices (USN)

+ [USN-2655-1](https://usn.ubuntu.com/USN-2655-1)
+ Tomcat vulnerabilities
+ 25 June 2015

+ [USN-2654-1](https://usn.ubuntu.com/USN-2654-1)
+ Tomcat vulnerabilities
+ 25 June 2015

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2014-0230>
