connection.c in Cherokee web server before 0.4.6 allows remote attackers to cause a denial of service via an HTTP POST request without a Content-Length header field.
https://exchange.xforce.ibmcloud.com/vulnerabilities/14119
http://www.securityfocus.com/bid/9345
http://secunia.com/advisories/10518
http://freshmeat.net/redir/cherokee/20646/url_changelog/ChangeLog