CVE-2007-0774

Publication date 4 March 2007

Last updated 17 July 2025


Ubuntu priority

Description

Stack-based buffer overflow in the map_uri_to_worker function (native/common/jk_uri_worker_map.c) in mod_jk.so for Apache Tomcat JK Web Server Connector 1.2.19 and 1.2.20, as used in Tomcat 4.1.34 and 5.5.20, allows remote attackers to execute arbitrary code via a long URL that triggers the overflow in a URI worker map routine.

Status

Package Ubuntu Release Status
tomcat5.5 8.04 LTS hardy
Not affected
7.10 gutsy
Not affected
7.04 feisty Ignored end of life, was needed
6.10 edgy
Not affected
6.06 LTS dapper Not in release


Access our resources on patching vulnerabilities