Sun Java System Active Server Pages Multiple Vulnerabilities

Posted on Friday, September 04, 2009 @ 00:42:31 UTC in Security
by Raven

SECUNIA ADVISORY ID: SA36586

VERIFY ADVISORY: http://secunia.com/advisories/36586/

DESCRIPTION: Some vulnerabilities have been reported in Sun Java System Active Server Pages, one having an unspecified impact, while others can be exploited by malicious users to compromise a vulnerable system and by malicious people to cause a DoS (Denial of Service). The vulnerabilities are reported in version 4.0.3. Other versions may also be affected.

1) Two unspecified errors can be exploited to cause stack-based buffer overflows. Successful exploitation may allow execution of arbitrary code, but may require valid user credentials.

2) An unspecified error can be exploited in the pre-authentication phase.

3) An unspecified error can be exploited to cause a "stack overflow".

SOLUTION: Restrict access to trusted users only.

PROVIDED AND/OR DISCOVERED BY: Reportedly a module for VulnDisco Pack.

ORIGINAL ADVISORY: http://intevydis.com/vd-list.shtml
 
 
click Related        click Share
 
News ©

Site Info

Last SeenLast Seen
  • neralex
  • nextgen
Server TrafficServer Traffic
  • Total: 482,287,209
  • Today: 5,474
Server InfoServer Info
  • Apr 18, 2024
  • 03:41 am UTC