Back

MEDIUM

Tomcat5 Data integrity

Published Feb 12, 2008

Description

Apache Tomcat 5.5.11 through 5.5.25 and 6.0.0 through 6.0.15, when the native APR connector is used, does not properly handle an empty request to the SSL port, which allows remote attackers to trigger handling of "a duplicate copy of one of the recent requests," as demonstrated by using netcat to send the empty request.

Affected products

Remediation

Red Hat statement

Not Vulnerable. Red Hat does not ship a version of Apache Tomcat that enables the native APR connector.

Metrics

References (38)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Feb 12, 2008
Updated Aug 7, 2024
Reserved Dec 10, 2007
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Feb 8, 2008
GHSA-QRJ4-RMQG-4HCP