Ravens PHP Scripts

Sun Java System Active Server Pages Multiple Vulnerabilities
Date: Friday, September 04, 2009 @ 01:42:31 CEST
Topic: Security


VERIFY ADVISORY: http://secunia.com/advisories/36586/

DESCRIPTION: Some vulnerabilities have been reported in Sun Java System Active Server Pages, one having an unspecified impact, while others can be exploited by malicious users to compromise a vulnerable system and by malicious people to cause a DoS (Denial of Service). The vulnerabilities are reported in version 4.0.3. Other versions may also be affected.

1) Two unspecified errors can be exploited to cause stack-based buffer overflows. Successful exploitation may allow execution of arbitrary code, but may require valid user credentials.

2) An unspecified error can be exploited in the pre-authentication phase.

3) An unspecified error can be exploited to cause a "stack overflow".

SOLUTION: Restrict access to trusted users only.

PROVIDED AND/OR DISCOVERED BY: Reportedly a module for VulnDisco Pack.

ORIGINAL ADVISORY: http://intevydis.com/vd-list.shtml

This article comes from Ravens PHP Scripts

The URL for this story is: