Apache Tomcat 5.5.11 through 5.5.25 and 6.0.0 through 6.0.15, when the native APR connector is used, does not properly handle an empty request to the SSL port, which allows remote attackers to trigger handling of "a duplicate copy of one of the recent requests," as demonstrated by using netcat to send the empty request.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2008-02-12T00:00:00
Updated: 2024-08-07T16:02:36.175Z
Reserved: 2007-12-10T00:00:00
Link: CVE-2007-6286
Vulnrichment
No data.
NVD
Status : Modified
Published: 2008-02-12T01:00:00.000
Modified: 2024-11-21T00:39:46.723
Link: CVE-2007-6286
Redhat