Summary
The remote host is missing an update to tomcat4
announced via advisory DSA 395-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20395-1
Insight
Aldrin Martoq has discovered a denial of service (DoS) vulnerability in Apache Tomcat 4.0.x. Sending several non-HTTP requests to Tomcat's HTTP connector makes Tomcat reject further requests on this port until it is restarted.
For the current stable distribution (woody) this problem has been fixed in version 4.0.3-3woody3.
For the unstable distribution (sid) this problem does not exist in the current version 4.1.24-2.
We recommend that you upgrade your tomcat4 packages and restart the
Severity
Classification
-
CVE CVE-2003-0866 -
CVSS Base Score: 5.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
Related Vulnerabilities