A flaw in Apache Tomcat could affect Cisco’s Wireless Control System, which manages and controls lightweight access

points, wireless LAN controllers, and Cisco Wireless Location Appliances. Cisco says the Apache Tomcat vulnerability could open the doors for remote code execution attacks because the mod_jk.so URI handler does not handle long URLs correctly. An insecure memory copy triggers an exploitable stack overflow, according to Cisco in its security advisory. Affected Cisco products are: WCS for Linux and Windows 4.0.x and earlier, and WCS for Linux and Windows 4.1.91.0 and earlier. Details about fixes and workaround are available at Cisco’s advisory.
More Cisco security advisories
More from Cisco Subnet:
* How far will Cisco’s Nexus enable Cisco to own the data center?
* Juniper finally releases enterprise switch
* Juniper CEO on why he can compete with Cisco in the enterprise
* How to pass the CCIE Voice written exam
* Understanding MPLS Label Stacking
* How Cisco is moving up the stack with Application Networking Solutions
* Cisco DPC3000 elixir of life for DOCSIS 3.0?
* Network Hardware Resale offers a lifeline to Cisco switches ineligible for SMARTnet
* Help us find useful Web sites for Cisco networking pros
* Win an iPod Touch; win a copy of ‘Firewall Fundamentals’ book
Go to Cisco Subnet for more Cisco news, blogs, discussion forums, security alerts, book giveaways, and more.
Recent Cisconet blog entries
Network World’s IT Buyer’s Guide: Cisco products
Subscribe to Network World’s Cisco Alert, which includes a weekly digest of all Cisco Subnet items




