PT-2002-2068 · Thomas Hauck · Thomas Hauck Jana Server

Published

2002-08-31

·

Updated

2008-09-05

·

CVE-2002-1062

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Thomas Hauck Jana Server versions 1.4.6 and earlier Thomas Hauck Jana Server versions 2.x through 2.2.1
Description: A signedness error in the software allows remote attackers to execute arbitrary code via long entries in the Username, Password, or Hostname fields.
Recommendations: For Thomas Hauck Jana Server versions 1.4.6 and earlier, update to a version later than 1.4.6. For Thomas Hauck Jana Server versions 2.x through 2.2.1, update to a version later than 2.2.1. As a temporary workaround, consider restricting the length of the Username, Password, and Hostname entries to prevent exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-1062

Affected Products

Thomas Hauck Jana Server