CVE-2007-0774
Stack-based buffer overflow in the map_uri_to_worker function (native/common/jk_uri_worker_map.c) in mod_jk.so for Apache Tomcat JK Web Server Connector 1.2.19 and 1.2.20, as used in Tomcat 4.1.34 and 5.5.20, allows remote attackers to execute arbitrary code via a long URL that triggers the overflow in a URI worker map routine.
- Affected products
- Apache Tomcat Jk Web Server Connector, Hp-Ux, Apache Tomcat
- Apache Tomcat Jk Web Server Connector
- = 1.2.19, 1.2.20
- Fix
- Available
- CVSS 2.0
- 7.5 HIGH
- EPSS
- 81.5% (100th percentile)
- NVD status
- Modified
- Published
- 2007-03-04
CVE-2007-0774 at NVD
9 known exploits for CVE-2007-0774
Proof-of-concept code and exploit modules indexed by Sploitus
Apache Tomcat mod_jk 1.2.20 - Remote Buffer Overflow (Metasploit)
Apache Tomcat JK Web Server Connector URI worker map buffer overflow
Apache Tomcat JK Web Server Connector URI worker map buffer overflow
Apache Tomcat JK Web Server Connector URI worker map buffer overflow
Apache Tomcat JK Web Server Connector URI worker map buffer overflow
apache_modjk_overflow.rb.txt
Apache Tomcat Connector mod_jk - 'exec-shield' Remote Overflow
Apache mod_jk 1.2.20 Buffer Overflow
DSquare Exploit Pack: D2SEC_MOD_JK