Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Gentoo Linux Security Advisory GLSA 200708-15
https://security.gentoo.org/
Severity: Low
Title: Apache mod_jk: Directory traversal
Date: August 19, 2007
Bugs: #186218
ID: 200708-15
Synopsis
=======
A directory traversal vulnerability has been discovered in Apache
mod_jk.
Background
=========
Apache mod_jk is a connector for the Tomcat web server.
Affected packages
================
-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 www-apache/mod_jk < 1.2.23 >= 1.2.23
==========
Apache mod_jk decodes the URL within Apache before passing them to
Tomcat, which decodes them a second time.
Impact
=====
A remote attacker could browse a specially crafted URL on an Apache
server running mod_jk, possib...
style>.gentoo_availability{display:block;}
Get the latest Linux and open source security news straight to your inbox.