jim_duffy
Managing Editor

Cisco warns Tomcat flaw could harm its Wireless Control System

Analysis
Jan 30, 20082 mins

A flaw in Apache Tomcat could affect Cisco’s Wireless Control System, which manages and controls lightweight access

points, wireless LAN controllers, and Cisco Wireless Location Appliances. Cisco says the Apache Tomcat vulnerability could open the doors for remote code execution attacks because the mod_jk.so URI handler does not handle long URLs correctly. An insecure memory copy triggers an exploitable stack overflow, according to Cisco in its security advisory. Affected Cisco products are: WCS for Linux and Windows 4.0.x and earlier, and WCS for Linux and Windows 4.1.91.0 and earlier. Details about fixes and workaround are available at Cisco’s advisory.  

More Cisco security advisories

More Cisco security responses

More from Cisco Subnet:

* How far will Cisco’s Nexus enable Cisco to own the data center?

 * Juniper finally releases enterprise switch

* Juniper CEO on why he can compete with Cisco in the enterprise

* How to pass the CCIE Voice written exam

* Understanding MPLS Label Stacking

* How Cisco is moving up the stack with Application Networking Solutions

* Cisco DPC3000 elixir of life for DOCSIS 3.0?

* Network Hardware Resale offers a lifeline to Cisco switches ineligible for SMARTnet

* Help us find useful Web sites for Cisco networking pros

* All you ever wanted to know about router security strategies, IP network traffic planes and more – just ask us

* Building your own CCNA lab

* Win an iPod Touch; win a copy of ‘Firewall Fundamentals’ book

Go to Cisco Subnet for more Cisco news, blogs, discussion forums, security alerts, book giveaways, and more.

Recent Cisconet blog entries

Network World’s IT Buyer’s Guide: Cisco products

Subscribe to Network World’s Cisco Alert, which includes a weekly digest of all Cisco Subnet items