CVE-2006-7197

Publication date 25 April 2007

Last updated 17 July 2025


Ubuntu priority

Description

The AJP connector in Apache Tomcat 5.5.15 uses an incorrect length for chunks, which can cause a buffer over-read in the ajp_process_callback in mod_jk, which allows remote attackers to read portions of sensitive memory.

Status

Package Ubuntu Release Status
tomcat5.5 7.04 feisty
Not affected
6.10 edgy
Not affected
6.06 LTS dapper Not in release


Access our resources on patching vulnerabilities