Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS1xcmo0LXJtcWctNGhjcM2skg

Apache Tomcat Does Not Properly Handle Empty Requests

Apache Tomcat 5.5.11 through 5.5.25 and 6.0.0 through 6.0.15, when the native APR connector is used, does not properly handle an empty request to the SSL port, which allows remote attackers to trigger handling of "a duplicate copy of one of the recent requests," as demonstrated by using netcat to send the empty request.

Permalink: https://github.com/advisories/GHSA-qrj4-rmqg-4hcp
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1xcmo0LXJtcWctNGhjcM2skg
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: about 2 years ago
Updated: 7 months ago


Identifiers: GHSA-qrj4-rmqg-4hcp, CVE-2007-6286
References: Blast Radius: 0.0

Affected Packages

maven:org.apache.tomcat:tomcat
Dependent packages: 30
Dependent repositories: 438
Downloads:
Affected Version Ranges: >= 6.0.0, <= 6.0.15, >= 5.5.11, <= 5.5.25
No known fixed version
All affected versions: