|
|
>> Sun Java System Web Proxy Server Denial of Service Vulnerability
|
Title : Sun Java System Web Proxy Server Denial of Service Vulnerability VUPEN ID : VUPEN/ADV-2008-2366 CVE ID : GENERIC-MAP-NOMATCH
Rated as : Moderate Risk 
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-08-13
|
A vulnerability has been identified in Sun Java System Web Proxy Server, which could be exploited by attackers to cause a denial of service. This issue is caused by an unspecified error in the FTP subsystem, which could allow a local or remote attacker to prevent a vulnerable proxy server from accepting new connections, resulting in a denial of service.
Affected Products
Sun Java System Web Proxy Server versions 4.0 through 4.0.5
Solution
Sun Java System Web Proxy Server versions 4.0 through 4.0.5 (SPARC) - Upgrade to Service Pack 6 or later, or apply patch 120981-14 or later
Sun Java System Web Proxy Server versions 4.0 through 4.0.5 (x86) - Upgrade to Service Pack 6 or later, or apply patch 120982-14 or later
Sun Java System Web Proxy Server versions 4.0 through 4.0.5 (Linux) - Upgrade to Service Pack 6 or later, or apply patch 120983-14 orlater
Sun Java System Web Proxy Server versions 4.0 through 4.0.5 (HP-UX) - Upgrade to Service Pack 6 or later, or apply patch 123532-04 or later
Sun Java System Web Proxy Server versions 4.0 through 4.0.5 (Windows) - Upgrade to Service Pack 6 or later, or apply patch 126325-04 or later
Or upgrade to Sun Java System Web Proxy Server version 4.0.7 :
http://www.sun.com/download/index.jsp?cat=Web%20%26%20Proxy%20Servers&tab=3
References
http://www.vupen.com/english/advisories/2008/2366 http://sunsolve.sun.com/search/document.do?assetkey=1-66-240327-1
Credits
Vulnerability reported by Joxean Koret.
ChangeLog
2008-08-13 : Initial release
Vulnerability Management
Subscribe to VUPEN VNS and receive real-time e-mail and SMS alerts when new advisories or patches relevant to your systems and network configurations are available.
Feedback
If you have additional information or corrections for this security advisory please submit them via our contact form. | |
|