Sun One Web server flaw can run attack code
- 12 August, 2002 08:35
- Comments
A security hole in Sun Microsystems Inc.'s Sun One and iPlanet Web servers can allow an attacker to launch a denial of service attack on the server and to run attack code of his or her choice, according to a security alert released Friday by eEye Digital Security Inc.
Using a specially formed request employing chunked transfer encoding, an attacker can cause a buffer overflow on the Web servers, which will crash them, according to a separate security alert released by Sun. This can allow an attacker to run malicious code, Sun said. Chunked transfer encoding is a feature allowing applications to maintain persistent connections without knowing the length of the expected content.
The vulnerability is remotely exploitable, meaning that an attacker who does not have physical access to the machine can launch an attack on affected systems.
The flaws affect iPlanet Web server 4.1 and Sun One Web server 6.0, according to the alerts.
Sun has released both a work around and service packs that fix the problem. Links to those downloads, as well as more information about the vulnerability, can be found at http://www.sun.com/service/support/software/iplanet/alerts/transferencodingalert-23july2002.html.
Another vulnerability involving chunked encoding was discovered in the Apache Web server in June.
- Bookmark this page
- Share this article
- Got more on this story? Email Computerworld
- Follow Computerworld on twitter
-
CeBIT 2012: Will NBN speed up freight delivery times?
-
Coalition NBN better or worse?
-
Coalition NBN better or worse?
-
CeBIT 2012: Will NBN speed up freight delivery times?
-
NBN build gaining momentum daily: Quigley
-
Teach Yourself Visually Windows 7
-
Windows 7 for Seniors for Dummies®
-
Windows 7 for Dummies®
-
MYOB Software for Dummies 6E Australian Edition
-
Excel 2007 All-In-One Desk Reference for Dummies
-
Windows 7 for Dummies® Dvd+book Bundle
-
Office 2007 for Dummies
-
Microsoft Office
-
Computers for Seniors for Dummies, 2nd Edition









Comments
Post new comment