Title : Apache Tomcat Connector mod_jk Library URL Handling Buffer Overflow Vulnerability VUPEN ID : VUPEN/ADV-2007-0809 CVE ID : CVE-2007-0774
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-03-05
Technical Description
A vulnerability has been identified in Apache Tomcat Connector, which could be exploited by attackers to compromise a vulnerable web server. This issue is due to a buffer overflow error in the mod_jk library when processing overly long URLs via the "map_uri_to_worker()" [native/common/jk_uri_worker_map.c] method, which could be exploited by remote attackers to execute arbitrary commands by sending a specially crafted request to an affected server.