Launch Week Day 1: Announcing Security Design Review
UNKNOWN Maven

Apache Tomcat Buffer Over-Read

GHSA-jpqr-vh55-xqxf · CVE-2006-7197

Published · Modified

Description

The AJP connector in Apache Tomcat 5.5.15 uses an incorrect length for chunks, which can cause a buffer over-read in the ajp_process_callback in mod_jk, which allows remote attackers to read portions of sensitive memory.

References

Ready to move

Start Securing

Free, no credit card | First findings in minutes