Updated mod_jk packages that fix a security issue are now available for Red
Hat Application Server v2.
This update has been rated as having critical security impact by the Red
Hat Security Response Team.
mod_jk is a Tomcat connector that can be used to communicate between Tomcat
and the Apache HTTP Server 2.
A stack overflow flaw was found in the URI handler of mod_jk. A remote
attacker could visit a carefully crafted URL being handled by mod_jk and
trigger this flaw, which could lead to the execution of arbitrary code as the
'apache' user. (CVE-2007-0774)
Users of mod_jk should upgrade to these updated packages, which contain a
backported patch to correct this issue.
Red Hat would like to thank TippingPoint and the Zero Day Initiative for
reporting this issue.
| Application Server v2 EL4 |
|
| SRPMS: |
mod_jk-1.2.20-1jpp_1rh.src.rpm
File outdated by: RHSA-2007:0380 |
86b65eda01d8eed6e6ac566ec8aacfd7 |
mod_jk-1.2.20-1jpp_1rh.src.rpm
File outdated by: RHSA-2007:0380 |
86b65eda01d8eed6e6ac566ec8aacfd7 |
mod_jk-1.2.20-1jpp_1rh.src.rpm
File outdated by: RHSA-2007:0380 |
86b65eda01d8eed6e6ac566ec8aacfd7 |
| |
| IA-32: |
mod_jk-ap20-1.2.20-1jpp_1rh.i386.rpm
File outdated by: RHSA-2007:0380 |
7cda766c03df94e7ee4666f6ef7b209d |
mod_jk-ap20-1.2.20-1jpp_1rh.i386.rpm
File outdated by: RHSA-2007:0380 |
7cda766c03df94e7ee4666f6ef7b209d |
mod_jk-ap20-1.2.20-1jpp_1rh.i386.rpm
File outdated by: RHSA-2007:0380 |
7cda766c03df94e7ee4666f6ef7b209d |
mod_jk-manual-1.2.20-1jpp_1rh.i386.rpm
File outdated by: RHSA-2007:0380 |
bfeeef22164ec43c86bfff19df932d01 |
mod_jk-manual-1.2.20-1jpp_1rh.i386.rpm
File outdated by: RHSA-2007:0380 |
bfeeef22164ec43c86bfff19df932d01 |
mod_jk-manual-1.2.20-1jpp_1rh.i386.rpm
File outdated by: RHSA-2007:0380 |
bfeeef22164ec43c86bfff19df932d01 |
| |
| IA-64: |
mod_jk-ap20-1.2.20-1jpp_1rh.ia64.rpm
File outdated by: RHSA-2007:0380 |
f7b7e208063488ce4f655663416a0106 |
mod_jk-ap20-1.2.20-1jpp_1rh.ia64.rpm
File outdated by: RHSA-2007:0380 |
f7b7e208063488ce4f655663416a0106 |
mod_jk-ap20-1.2.20-1jpp_1rh.ia64.rpm
File outdated by: RHSA-2007:0380 |
f7b7e208063488ce4f655663416a0106 |
mod_jk-manual-1.2.20-1jpp_1rh.ia64.rpm
File outdated by: RHSA-2007:0380 |
6e24470476ae0ba1b1fd7052cecefd48 |
mod_jk-manual-1.2.20-1jpp_1rh.ia64.rpm
File outdated by: RHSA-2007:0380 |
6e24470476ae0ba1b1fd7052cecefd48 |
mod_jk-manual-1.2.20-1jpp_1rh.ia64.rpm
File outdated by: RHSA-2007:0380 |
6e24470476ae0ba1b1fd7052cecefd48 |
| |
| PPC: |
mod_jk-ap20-1.2.20-1jpp_1rh.ppc.rpm
File outdated by: RHSA-2007:0380 |
15150412247dfab9d2da8431ed619f13 |
mod_jk-manual-1.2.20-1jpp_1rh.ppc.rpm
File outdated by: RHSA-2007:0380 |
86a13a0f8af30bef2058b1519219f888 |
| |
| x86_64: |
mod_jk-ap20-1.2.20-1jpp_1rh.x86_64.rpm
File outdated by: RHSA-2007:0380 |
0c08848f81140f537bf5ec02cad1a3a2 |
mod_jk-ap20-1.2.20-1jpp_1rh.x86_64.rpm
File outdated by: RHSA-2007:0380 |
0c08848f81140f537bf5ec02cad1a3a2 |
mod_jk-ap20-1.2.20-1jpp_1rh.x86_64.rpm
File outdated by: RHSA-2007:0380 |
0c08848f81140f537bf5ec02cad1a3a2 |
mod_jk-manual-1.2.20-1jpp_1rh.x86_64.rpm
File outdated by: RHSA-2007:0380 |
6bafe48e502b46ce7f64945886da350e |
mod_jk-manual-1.2.20-1jpp_1rh.x86_64.rpm
File outdated by: RHSA-2007:0380 |
6bafe48e502b46ce7f64945886da350e |
mod_jk-manual-1.2.20-1jpp_1rh.x86_64.rpm
File outdated by: RHSA-2007:0380 |
6bafe48e502b46ce7f64945886da350e |
| |
(The unlinked packages above are only available from the Red Hat Network)
|
236182 - CVE-2007-0774 mod_jk overflow flaw