CVE-2007-6286

Description

From CVE.org

Apache Tomcat 5.5.11 through 5.5.25 and 6.0.0 through 6.0.15, when the native APR connector is used, does not properly handle an empty request to the SSL port, which allows remote attackers to trigger handling of "a duplicate copy of one of the recent requests," as demonstrated by using netcat to send the empty request.

Statement

Not Vulnerable. Red Hat does not ship a version of Apache Tomcat that enables the native APR connector.

Frequently Asked Questions

Want to get errata notifications? Sign up here.