PT-2010-2147 · Sun · Sun Java System Web Server

Published

2010-01-20

·

Updated

2011-04-28

·

CVE-2010-0361

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Sun Java System Web Server versions 7.0 Update 7
Description The issue is related to a stack-based buffer overflow in the WebDAV implementation. This can be triggered by sending an HTTP OPTIONS request with a long URI, potentially causing a denial of service (daemon crash) and possibly other unspecified impacts.
Recommendations For Sun Java System Web Server version 7.0 Update 7, consider restricting access to the WebDAV implementation until a fix is available. As a temporary workaround, limit the length of URIs accepted by the server to prevent exploitation.

Exploit

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-0361

Affected Products

Sun Java System Web Server