PT-2004-1734 · Apache+1 · Apache+1
Publicado
2004-11-19
·
Atualizado
2017-07-11
·
CVE-2004-0646
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
JRun versions 3.0 through 4.0
Description
The issue is related to a buffer overflow in the WriteToLog function when verbose logging is enabled. This can be exploited by remote attackers to execute arbitrary code via a long HTTP header Content-Type field or other fields.
Recommendations
For JRun versions 3.0 through 4.0, consider disabling verbose logging as a temporary workaround to minimize the risk of exploitation. Restrict access to the WriteToLog function until a patch is available. Avoid using the Content-Type field in HTTP headers with overly long values in the affected web server connectors, such as mod jrun and mod jrun20 for Apache, until the issue is resolved.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Apache
Jrun