PDA

View Full Version : CVE-2008-3271 - Apache Tomcat information disclosure via RemoteFilterValve


kjkoster
10-10-2008, 13:24
Dear All,

Here is one from the Tomcat developer list (http://www.mail-archive.com/users@tomcat.apache.org/msg51690.html): a race condition (http://en.wikipedia.org/wiki/Race_condition#Computing) in the RemoteFilterValve that may cause the valve to accept a client that should be blocked.

Tomcat 4.1.31 and older are vulnerable, as is 5.5.0 and older. The 6.0.x branch is not affected.

Kees Jan

kjkoster
15-10-2008, 08:36
Dear All,

Here is the actual CVE link (http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-3271) for this vulnerability.

Kees Jan

triks123
18-11-2008, 11:45
thanks you for your post, you help is appreciated