SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#703835

Macromedia JRun ISAPI DLL filter vulnerable to buffer overflow via request for long Host header field

Overview

A remotely exploitable buffer overflow exists in Macromedia's JRun version 3.1 on Win32 platforms.

I. Description

A remotely exploitable buffer overflow exists in the Win32 version of Macromedia's JRun version 3.1 on Win32 platforms.

JRun is an application server that works with most popular web servers such as Apache and IIS. Macromedia states that JRun is deployed at over 10,000 organizations worldwide.

As reported in the Next Generation Security Software Advisory (#NISR29052002), a remotely exploitable buffer overflow exists in the ISAPI filter/application. Specifically, the buffer overflow exists in the portion of code that handles the host header field. If an attacker sends a specially crafted request to the application server, he can overwrite a return address on the stack. Because the vulnerable DLL is running in the address space of the web server process (at least on IIS 4 & 5), code submitted by the attacker will be run with SYSTEM privileges.

II. Impact

A remote attacker can execute arbitrary code on the vulnerable target with SYSTEM privileges.

III. Solution

Apply the patch from Macromedia Inc. or upgrade to JRun 4.

None.

Systems Affected

VendorStatusDate NotifiedDate Updated
Macromedia Inc.Vulnerable29-May-2002

References


http://www.macromedia.com/v1/handlers/index.cfm?ID=23164
http://www.ngssoftware.com/advisories/jrun.txt
http://www.macromedia.com/software/jrun/
http://www.macromedia.com
http://www.securityfocus.com/bid/4873

Credit

This vulnerability was discovered by David Litchfield of Next Generation Security Software.

This document was written by Ian A. Finlay.

Other Information

Date Public:2002-05-29
Date First Published:2002-05-29
Date Last Updated:2003-04-09
CERT Advisory: 
CVE-ID(s):CAN-2002-0801
NVD-ID(s):CAN-2002-0801
US-CERT Technical Alerts: 
Metric:54.00
Document Revision:53

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Copyright 2002 Carnegie Mellon University
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader