This application requires Javascript for optimal performance.

Sun.Java.System.Web.Server.WEBDAV.Stack.Buffer.Overflow

Release Date

Mar 16, 2010

Severity

critical

Impact

System Compromise
Denial of Service

Description

This indicates an attack attempt against a buffer overflow vulnerability in Sun Java System Web Server.

The vulnerability is caused by an error when the vulnerable software handles a specially crafted HTTP request. It allows a remote attacker to execute arbitrary code.

Affected Products

Sun Java System Web Server 7.0 Update 7
Sun Java System Web Server 7.0 Update 6
Sun Java System Web Server 7.0 Update 3
Sun Java System Web Server 7.0 Update 2
Sun Java System Web Server 7.0 Update 1

Recommended Actions

Update to the latest versions:

http://wwws.sun.com/software/products/web_srvr/home_web_srvr.html

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2010-0361

Reference/s

http://www.securityfocus.com/bid/37874 (BugTraq)

Reference: VID-18249