PT-2007-2222 · Apache+1 · Apache Tomcat Jk Web Server Connector+2

Publicado

2007-03-04

·

Atualizado

2024-06-15

·

CVE-2007-0774

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Apache Tomcat JK Web Server Connector versions 1.2.19 through 1.2.20 Tomcat versions 4.1.34 and 5.5.20
Description The issue is a stack-based buffer overflow in the map uri to worker function, located in the jk uri worker map.c file of the mod jk.so module. This allows remote attackers to execute arbitrary code via a long URL that triggers the overflow in a URI worker map routine.
Recommendations For Apache Tomcat JK Web Server Connector versions 1.2.19 and 1.2.20, consider updating to a version that is not affected by this issue. For Tomcat versions 4.1.34 and 5.5.20, consider updating to a version that is not affected by this issue. As a temporary workaround, consider restricting access to long URLs to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-0774
HPSBUX02262
OPENSUSE-SU-2024:10625-1
RHSA-2007:0096
RHSA-2007:0164

Produtos afetados

Apache Tomcat Jk Web Server Connector
Hp-Ux
Apache Tomcat