PT-2007-2222 · Apache+1 · Apache Tomcat Jk Web Server Connector+2

Published

2007-03-04

·

Updated

2024-06-15

·

CVE-2007-0774

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Apache Tomcat JK Web Server Connector versions 1.2.19 through 1.2.20 Tomcat versions 4.1.34 and 5.5.20
Description The issue is a stack-based buffer overflow in the map uri to worker function, located in the jk uri worker map.c file of the mod jk.so module. This allows remote attackers to execute arbitrary code via a long URL that triggers the overflow in a URI worker map routine.
Recommendations For Apache Tomcat JK Web Server Connector versions 1.2.19 and 1.2.20, consider updating to a version that is not affected by this issue. For Tomcat versions 4.1.34 and 5.5.20, consider updating to a version that is not affected by this issue. As a temporary workaround, consider restricting access to long URLs to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-0774
HPSBUX02262
OPENSUSE-SU-2024:10625-1
RHSA-2007:0096
RHSA-2007:0164

Affected Products

Apache Tomcat Jk Web Server Connector
Hp-Ux
Apache Tomcat