Updated mod_jk packages that fix a security issue are now available for Red
Hat Application Server v2.
This update has been rated as having critical security impact by the Red
Hat Security Response Team.
mod_jk is a Tomcat connector that can be used to communicate between Tomcat
and the Apache HTTP Server 2.
A stack overflow flaw was found in the URI handler of mod_jk. A remote
attacker could visit a carefully crafted URL being handled by mod_jk and
trigger this flaw, which could lead to the execution of arbitrary code as the
'apache' user. (CVE-2007-0774)
Users of mod_jk should upgrade to these updated packages, which contain a
backported patch to correct this issue.
Red Hat would like to thank TippingPoint and the Zero Day Initiative for
reporting this issue.