Debian Security Advisory 3278-1

Discussion in 'News Aggregator' started by Packet Storm, 8 Jun 2015.

  1. Packet Storm

    Packet Storm Guest

    Debian Linux Security Advisory 3278-1 - An information disclosure flaw due to incorrect JkMount/JkUnmount directives processing was found in the Apache 2 module mod_jk to forward requests from the Apache web server to Tomcat. A JkUnmount rule for a subtree of a previous JkMount rule could be ignored. This could allow a remote attacker to potentially access a private artifact in a tree that would otherwise not be accessible to them.

    Continue reading...
     

Share This Page

Loading...