PT-2002-2068 · Thomas Hauck · Thomas Hauck Jana Server
Published
2002-08-31
·
Updated
2008-09-05
·
CVE-2002-1062
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Thomas Hauck Jana Server versions 1.4.6 and earlier
Thomas Hauck Jana Server versions 2.x through 2.2.1
Description:
A signedness error in the software allows remote attackers to execute arbitrary code via long entries in the
Username, Password, or Hostname fields.Recommendations:
For Thomas Hauck Jana Server versions 1.4.6 and earlier, update to a version later than 1.4.6.
For Thomas Hauck Jana Server versions 2.x through 2.2.1, update to a version later than 2.2.1.
As a temporary workaround, consider restricting the length of the
Username, Password, and Hostname entries to prevent exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Thomas Hauck Jana Server