|
|
Sun ONE and Sun Java System Directory Servers LDAP Buffer Overflow |
|
Title : Sun ONE and Sun Java System Directory Servers LDAP Buffer Overflow Advisory ID : FrSIRT/ADV-2005-0352 CVE ID : CVE-2004-1236 CWE ID : CWE-
Rated as : Moderate Risk 
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-04-14
|
|
A vulnerability has identified in Sun ONE and Sun Java System Directory Servers, which could be exploited by a remote attacker to cause a denial of service or execute arbitrary commands [...]
Solution
Upgrade to Sun ONE Directory Server 5.1 SP4 or later :
http://www.sun.com/download/products.xml?id=42155636
Apply patch for Sun Java System Directory Server 5.2 (Solaris 8, 9, and 10 on SPARC) :
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21-115614-20-1
Apply patch for Sun Java System Directory Server 5.2 (Solaris 8, 9, and 10 on x86) :
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21-115615-20-1
Apply patch for Sun Java System Directory Server 5.2 (Linux) :
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21-118080-05-1
Apply patch for PatchZIP version of Sun Java System Directory Server 5.2 (Solaris 8, 9, and 10 on SPARC) :
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21-117665-02-1
Apply patch for PatchZIP version of Sun Java System Directory Server 5.2 (Solaris 8, 9, and 10 on x86) :
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21-117666-02-1
Apply patch for PatchZIP version of Sun Java System Directory Server 5.2 (Linux) :
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21-117668-02-1
Apply patch for PatchZIP version of Sun Java System Directory Server 5.2 (Windows) :
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21-117667-02-1
Apply patch for PatchZIP version of Sun Java System Directory Server 5.2 (HP-UX) :
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21-117669-02-1
Apply patch for PatchZIP version of Sun Java System Directory Server 5.2 (AIX) :
http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21-117670-02-1
ChangeLog
2005-04-14 : Initial release
2008-10-08 : Updated Advisory
Vulnerability Management
Subscribe to FrSIRT VNS and receive real-time e-mail and SMS alerts when new vulnerabilities, exploits, or patches relevant to your systems and network configurations are available.
Feedback
If you have additional information or corrections for this security advisory please submit them via our contact form or by email to updates@frsirt.com.
| |
|