MGASA-2015-0254
Dashboard / Vulnerabilities / MGASA-2015-0254
Summary: Updated apache-mod_jk package fixes security vulnerability
Details: An information disclosure flaw due to incorrect JkMount/JkUnmount directives processing was found in the Apache 2 module mod_jk to forward requests from the Apache web server to Tomcat. A JkUnmount rule for a subtree of a previous JkMount rule could be ignored. This could allow a remote attacker to potentially access a private artifact in a tree that would otherwise not be accessible to them (CVE-2014-8111).
References: https://advisories.mageia.org/MGASA-2015-0254.html, https://bugs.mageia.org/show_bug.cgi?id=16078, https://www.debian.org/security/2015/dsa-3278
Affected packages
Package
Name: apache-mod_jk
Purl: pkg:rpm/mageia/apache-mod_jk?arch=source&distro=mageia-4
Affected ranges
Type: ECOSYSTEM
Events:
