Several flaws in the handling of the 'Transfer-Encoding' header were found that prevented the recycling of a buffer. A remote attacker could trigger this flaw which would cause subsequent requests to fail and/or information to leak between requests. This flaw is mitigated if Tomcat is behind a reverse proxy (such as Apache httpd 2.2) as the proxy should reject the invalid transfer encoding header. Одним словом предлагаю обновить Tomcat до 6.0.28, который также зафиксит #23500
tomcat6-0:6.0.26-alt2_11jpp6 -> sisyphus: * Mon Oct 18 2010 Igor Vlasenko <viy@altlinux> 0:6.0.26-alt2_11jpp6 - CVE-2010-2227 fix (closes: 23779)