Updated mod_jk packages that fix a security issue are now available for Red
Hat Application Stack v1.1.
This update has been rated as having critical security impact by the Red
Hat Security Response Team.
mod_jk is a Tomcat connector that can be used to communicate between Tomcat
and the Apache HTTP Server 2. mod_jk was first distributed with Red Hat
Application Stack version 1.1 released on 19 February 2007.
A stack overflow flaw was found in the URI handler of mod_jk. A remote
attacker could visit a carefully crafted URL being handled by mod_jk and
trigger this flaw, which could lead to the execution of arbitrary code as the
'apache' user. (CVE-2007-0774)
Users of mod_jk should upgrade to these updated packages, which contain a
backported patch to correct this issue.
Red Hat would like to thank TippingPoint and the Zero Day Initiative for
reporting this issue.