RedHat Security Advisory RHSA-2009:1087

The remote host is missing updates announced in advisory RHSA-2009:1087. mod_jk is an Apache Tomcat connector that allows Apache Tomcat and the Apache HTTP Server to communicate with each other. An information disclosure flaw was found in mod_jk. In certain situations, if a faulty client set the Content-Length header without providing data, or if a user sent repeated requests very quickly, one user may view a response intended for another user. (CVE-2008-5519) All mod_jk users are advised to upgrade to these updated packages. They provide mod_jk 1.2.28, which is not vulnerable to this issue.
Please note that this update is available via Red Hat Network. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date