Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug
Bug#: 186218
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Sune Kloppenborg Jeppesen <jaervosz@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 186218 depends on: Show dependency tree
Bug 186218 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2007-07-22 12:26 0000
mod_jk in Apache Tomcat JK Web Server Connector 1.2.x before 1.2.23 decodes
request URLs within the Apache HTTP Server before passing the URL to Tomcat,
which allows remote attackers to access protected pages via a crafted prefix
JkMount, possibly involving double-encoded .. (dot dot) sequences and directory
traversal, a related issue to CVE-2007-0450.

------- Comment #1 From Pierre-Yves Rofes 2007-07-22 14:01:06 0000 -------
version 1.2.23 is already in the tree but unstable, are we ready to call arches
for stabilisation? William, please advise.

------- Comment #2 From William L. Thomson Jr. (RETIRED) 2007-07-22 16:31:45 0000 -------
Yes we should be good to go for stabilization. Sorry I had not requested it
sooner, kinda been tied up with other things. CC'ing archs now for
stabilization of 1.2.23.

------- Comment #3 From Christian Faulhammer 2007-07-25 09:21:19 0000 -------
x86 stable

------- Comment #4 From William L. Thomson Jr. (RETIRED) 2007-07-25 15:05:05 0000 -------
amd64 stable

------- Comment #5 From Tobias Scherbaum 2007-07-27 21:04:13 0000 -------
ppc stable, ready for glsa-voting. on a side-note: debian and red hat released
advisories.

------- Comment #6 From Sune Kloppenborg Jeppesen 2007-07-28 07:42:11 0000 -------
I vote YES.

------- Comment #7 From Pierre-Yves Rofes 2007-07-29 22:07:08 0000 -------
voting yes too, let's have a GLSA on this one.

------- Comment #8 From Raphael Marichez 2007-08-19 23:01:20 0000 -------
GLSA 200708-15, thanks everybody

Bug List: (This bug is not in your last search results)   Show last search results      Search page      Enter new bug