Title:Apache News Online
Description:Keywords:Body:
Apache News Online
Apache News Online
April 08, 2009
07 April 2009 - CVE-2008-5519: Apache Tomcat mod_jk information disclosure vulnerability
CVE-2008-5519: Apache Tomcat mod_jk information disclosure vulnerability
Severity: important
Vendor: The Apache Software Foundation
Versions Affected:
mod_jk 1.2.0 to 1.2.26
Description:
Situations where faulty clients set Content-Length without providing
data, or where a user submits repeated requests very quickly may permit
one user to view the response associated with a different user's request.
Mitigation:
Upgrade to mod_jk 1.2.27 or later
Example:
See description
Credit:
This issue was discovered by the Red Hat Security Response Team
References:
http://tomcat.apache.org/security.html
http://tomcat.apache.org/security-jk.html
The Apache Tomcat Security Team
----Project Info -- Apache Tomcat ConnectorsApache Tomcat Connector (mod_jk)Releases can be downloaded from http://tomcat.apache.org/download-connectors.cgiProject Websitehttp://tomcat.apache.org/connectors-doc/Programming LanguagesJavaCategorieshttpd-moduleMailing Listshttp://tomcat.apache.org/lists.htmlBug/Issue Trackerhttp://issues.apache.org/bugzilla/enter_bug.cgi?product=Tomcat%206Project Management CommitteeApache TomcatAccess to the source code:Browsehttp://svn.apache.org/viewvc/tomcat/connectors/trunk/SVN Directhttp://svn.apache.org/repos/asf/tomcat/connectors/trunk/
Posted by Tetsuya Kitahata at April 8, 2009 01:39 AM
http://www.apachenews.org/archives/001300.html
[ Category : Apache Tomcat ] (PDF)(XML)
eCosway
.JP DomainAdult CostumesLaser PrintersDrug and Alcohol TreatmentRegister International Domain NameMonitorssecurity camera systemsOffice Supplies
Recent Entries
07 April 2009 - CVE-2008-5519: Apache Tomcat mod_jk information disclosure vulnerability
Categories
Links
ASF Projects
GMANE
MARC
OpenSource.org
AGEL
Syndication
Syndicate this site (RDF)
Syndicate this site (RSS)
Syndicate this site (ATOM)
FeedBurner(ApacheNewsOnline)
News Items?
Please post news related to apache.org to announce.AT.apachenews.org
Feedbacks
Appreciate your feedback to tetsuya.AT.apachenews.org.
Hosted By
Special Thanks
Terra-International, Inc.
Talents.JP(list)
Jewelry(Luxury)
College Web
Nihonkabu.JP
RMT
Denki
eCosway
Photo
Game2
AGEL (ENGLISH)
AGEL (GERMAN)
AGEL (SPANISH)
AGEL (FRENCH)
AGEL (ARABIC)
AGEL (PORTUGUESE)
AGEL (KOREA)
AGEL (CHINA)
AGEL (TAIWAN)
AGEL (HONGKONG)
AGEL (TURKISH)
AGEL (RUSSIAN)
AGEL (MALAY)
AGEL (INDONESIA)
AGEL (PERSIAN)
AGEL (JAPAN)
AGEL (POLISH)
AGEL (JAPAN)
Team-TERRA
Search
Search this site: