CVE-2002-2272: Buffer Overflow
Tomcat 4.0 through 4.1.12, using modjk 1.2.1 module on Apache 1.3 through 1.3.27, allows remote attackers to cause a denial of service (desynchronized communications) via an HTTP GET request with a Transfer-Encoding chunked field with invalid values.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2002-2272?
CVE-2002-2272 has a severity rating that indicates it allows denial of service attacks, affecting the availability of the system.
How do I fix CVE-2002-2272?
To fix CVE-2002-2272, upgrade Apache Tomcat to a version later than 4.1.12 or Apache HTTP Server to a version that is not affected by this vulnerability.
What systems are affected by CVE-2002-2272?
CVE-2002-2272 affects Apache Tomcat versions 4.0.0 through 4.1.12 and Apache HTTP Server versions 1.3 through 1.3.27 using the mod_jk module.
What kind of attack can CVE-2002-2272 be used for?
CVE-2002-2272 can be exploited by an attacker to perform a denial of service attack through desynchronized communications.
Is CVE-2002-2272 still a relevant concern?
While CVE-2002-2272 is considered an older vulnerability, it is still important to ensure that any systems running affected versions are patched to prevent exploitation.