Do You PHP はてブロ

Do You PHPはてなからはてブロに移動しました

mod_jk1.2.19/1.2.20に脆弱性

Apache Tomcat JK Connector – yohgaki's blogから。うきゃ〜!入れ直しですか。。。orz


The Apache Tomcat team is proud to announce the immediate availability of Tomcat Connectors 1.2.21. This is a stable release adding new features and a few bug fixes to version 1.2.20.
It fixes a Critical vulnerability introduced in version 1.2.19
Please see the ChangeLog for a full list of changes.

ChangeLogは次のような感じ。4095バイト以上のURLの場合、map_uri_to_worker()でバッファオーバーフローが発生するとのこと。


CVE-2007-0774 : A denial of service and critical remote code execution vulnerability. Caused by buffer overflow in map_uri_to_worker() when URL were longer that 4095 bytes.

あとは、jkstatus周りのFIXでしょうか。