|
|
| |
| When using the native (APR based) connector, connecting to the SSL port using netcat and then disconnecting without sending any data will cause Tomcat to handle a duplicate copy of one of the recent requests. |
| |
Credit:
The information has been provided by Mark Thomas.
The original article can be found at: http://tomcat.apache.org/security.html
|
| |
Vulnerable Systems:
* Tomcat version 5.5.11 up to 5.5.25
* Tomcat version 6.0.0 up to 6.0.15
Immune Systems:
* Tomcat version 5.5.26
* Tomcat version 6.0.16
CVE Information:
CVE-2007-6286
|
|
|
|
|