ubuntu · CVE-2007-0450

Quick triage

Priority: medium Published: 2007-03-16 22:19:00 UTC Updated: 2025-07-17 16:40:31 UTC

View at Official ubuntu advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2007-0450 medium priority: Ubuntu including 2 source packages (tomcat5, tomcat5.5), 18 status rows across 9 suites (dapper, edgy, feisty, gutsy, hardy, intrepid, jaunty, karmic, upstream): DNE 7, ignored 5, not-affected 4, needs-triage 2.

Description:

Directory traversal vulnerability in Apache HTTP Server and Tomcat 5.x before 5.5.22 and 6.x before 6.0.10, when using certain proxy modules (mod_proxy, mod_rewrite, mod_jk), allows remote attackers to read arbitrary files via a .. (dot dot) sequence with combinations of (1) "/" (slash), (2) "\" (backslash), and (3) URL-encoded backslash (%5C) characters in the URL, which are valid separators in Tomcat but not in Apache.

cvelogic Threat Intelligence