LWN.net Logo

apache tomcat: restriction bypass

Package(s):tomcat5, apache-jakarta-tomcat-connectors CVE #(s):CVE-2008-3271
Created:October 31, 2008 Updated:November 5, 2008
Description: From the CVE entry: Apache Tomcat 5.5.0 and 4.1.0 through 4.1.31 allows remote attackers to bypass an IP address restriction and obtain sensitive information via a request that is processed concurrently with another request but in a different thread, leading to an instance-variable overwrite associated with a "synchronization problem" and lack of thread safety, and related to RemoteFilterValve, RemoteAddrValve, and RemoteHostValve.
Alerts:
SuSE SUSE-SR:2008:023 2008-10-31

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds