Title : Apache mod_jk2 Host Header Multiple Buffer Overflow Vulnerabilities VUPEN ID : VUPEN/ADV-2008-0572 CVE ID : CVE-2007-6258
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-02-15
Technical Description
Multiple vulnerabilities have been identified in mod_jk2 for Apache, which could be exploited by remote attackers to cause a denial of service or compromise an affected web server. These issues are caused by buffer overflow errors when processing requests containing a malformed or overly long "Host" header, which could be exploited by remote attackers to crash an affected server or execute arbitrary code via a specially crafted request.