Apache Tomcat 6.x before 6.0.37 and 7.x before 7.0.30 does not properly handle chunk extensions in chunked transfer coding, which allows remote attackers to cause a denial of service by streaming data.
http://www.vmware.com/security/advisories/VMSA-2014-0012.html
http://www.ubuntu.com/usn/USN-1841-1
http://www.securityfocus.com/bid/64758
http://www.securityfocus.com/bid/59797
http://www.securityfocus.com/archive/1/534161/100/0/threaded
http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html
http://www.oracle.com/technetwork/topics/security/cpujan2014-1972949.html
http://tomcat.apache.org/security-7.html
http://tomcat.apache.org/security-6.html
http://svn.apache.org/viewvc?view=revision&revision=1476592
http://svn.apache.org/viewvc?view=revision&revision=1378921
http://svn.apache.org/viewvc?view=revision&revision=1378702
http://seclists.org/fulldisclosure/2014/Dec/23
http://archives.neohapsis.com/archives/bugtraq/2013-05/0042.html