SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

 

Vulnerability Note VU#746889

Sun Java System Web Proxy Server fails to properly process malformed packets

Overview

A vulnerability in the way Sun Java System Web Proxy Server processes malformed packets may allow execution of arbitrary code.

I. Description

SOCKS is a network protocol that provides a framework that allows client-server applications to securely use network firewall services. A vulnerability exists in the way Sun Java System Web Proxy Server handles specially crafted SOCKS packets. According to iDefense Security Advisory 05.25.07:

    The problem specifically exists within the "sockd" daemon. This daemon implements SOCKS proxy support for the Web Proxy product. Attackers can cause a buffer overflow by manipulating certain bytes during protocol negotiation.

II. Impact

An unauthenticated attacker on the local network may be able to execute arbitrary code with the privileges of the SOCKS server or cause a denial of service.

III. Solution

Update

Sun has addressed this issue in Sun Alert Notification 102927.

Disable SOCKS proxy server

Disable the SOCKS proxy server if it is not needed. According to Sun Alert Notification 102927:

    This can be accomplished by shutting down the SOCKS server using the 'stop-sockd' script under the Proxy Server instance directory.

Systems Affected

VendorStatusDate NotifiedDate Updated
Sun Microsystems, Inc.Vulnerable30-May-2007

References


http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=536
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102927-1
http://secunia.com/advisories/25405/

Credit

This issue is addressed in Sun Alert Notification 102927. Sun credits iDefense for reporting this issue.

This document was written by Chris Taschner.

Other Information

Date Public:2007-05-25
Date First Published:2007-05-30
Date Last Updated:2007-09-27
CERT Advisory: 
CVE-ID(s):CVE-2007-2881
NVD-ID(s):CVE-2007-2881
US-CERT Technical Alerts: 
Metric:17.86
Document Revision:11

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2007 by US-CERT, a government organization
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader