Vulnerability CVE-2016-6808


Published: 2017-04-12

Description:
Buffer overflow in Apache Tomcat Connectors (mod_jk) before 1.2.42.

See advisories in our WLB2 database:
Topic
Author
Date
High
Apache Tomcat JK ISAPI Connector 1.2.41 Buffer Overflow
Mark Thomas
12.10.2016

Type:

CWE-119

(Improper Restriction of Operations within the Bounds of a Memory Buffer)

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Apache -> Tomcat jk web server connector 
Apache -> Tomcat jk connector 

 References:
http://packetstormsecurity.com/files/139071/Apache-Tomcat-JK-ISAPI-Connector-1.2.41-Buffer-Overflow.html
http://rhn.redhat.com/errata/RHSA-2016-2957.html
http://seclists.org/fulldisclosure/2016/Oct/44
http://tomcat.apache.org/security-jk.html
http://www.openwall.com/lists/oss-security/2016/10/06/4
http://www.securityfocus.com/bid/93429
http://www.securitytracker.com/id/1036969
https://access.redhat.com/errata/RHSA-2017:0193
https://access.redhat.com/errata/RHSA-2017:0194
https://lists.apache.org/thread.html/277d42b48b6e9aef50949c0dcc79ce21693091d73da246b3c1981925@%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/5b7a23e245c93235c503900da854a143596d901bf1a1f67e851a5de4@%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/8d2a579bbd977c225c70cb23b0ec54865fb0dab5da3eff1e060c9935@%3Cdev.tomcat.apache.org%3E
https://lists.apache.org/thread.html/ba661b0edd913b39ff129a32d855620dd861883ade05fd88a8ce517d@%3Cdev.tomcat.apache.org%3E

Copyright 2024, cxsecurity.com

 

Back to Top