Netscape.SSLv2.Heap.Overflow
Description
This indicates an attack attempt to exploit a heap-overflow vulnerability in Netscape SSL.
The Netscape Network Security Services (NSS) library is vulnerable to a heap-overflow attack. There is a flaw when handling modified record length fields in an SSLv2 client hello message which can be exploited by an attacker. A successful exploit can lead to the execution of arbitrary code and system compromise.
Affected Products
Mozilla Network Security Services (NSS) 3.2 - 3.9
Netscape Certificate Server 1.0 P1
Netscape Certificate Server 4.2
Netscape Directory Server 1.3 P5
Netscape Directory Server 3.1 P1 4.13
Netscape Enterprise Server 2.0 - 4.1
Sun Java System Application Server 7.0 - 7.1
Sun ONE Web Server 4.1 - 6.2 SP2
Impact
System Compromise: Remote attackers can gain control of vulnerable systems.
Recommended Actions
Apply appropriate patches from the following references:
Sun Java Enterprise System 2003Q4
* Sun 114045-12
Solaris 8 Sparc::
* Sun 114049-12
Solaris 9 Sparc::
* Sun 114050-12
Solaris 9 x86:
* Sun 115924-09
Solaris 8 Sparc:
* Sun 115926-10
Solaris 9 Sparc:
* Sun 115927-10
Solaris 9 x86
Mozilla Network Security Services (NSS) 3.2
* Mozilla NSS_3_9_2_RTM:
ftp://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_9_2_ RTM/
Mozilla Network Security Services (NSS) 3.2.1
* Mozilla NSS_3_9_2_RTM:
ftp://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_9_2_ RTM/
Mozilla Network Security Services (NSS) 3.3
* Mozilla NSS_3_9_2_RTM:
ftp://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_9_2_ RTM/
Mozilla Network Security Services (NSS) 3.3.2
* Mozilla NSS_3_9_2_RTM:
ftp://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_9_2_ RTM/
Mozilla Network Security Services (NSS) 3.4
* Mozilla NSS_3_9_2_RTM:
ftp://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_9_2_ RTM/
Mozilla Network Security Services (NSS) 3.5
* Mozilla NSS_3_9_2_RTM:
ftp://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_9_2_ RTM/
Mozilla Network Security Services (NSS) 3.6.1
* Mozilla NSS_3_9_2_RTM:
ftp://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_9_2_ RTM/
Mozilla Network Security Services (NSS) 3.7.2
* Mozilla NSS_3_9_2_RTM:
ftp://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_9_2_ RTM/
Mozilla Network Security Services (NSS) 3.7.3
* Mozilla NSS_3_9_2_RTM:
ftp://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_9_2_ RTM/
Mozilla Network Security Services (NSS) 3.7.5
* Mozilla NSS_3_9_2_RTM:
ftp://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_9_2_ RTM/
Mozilla Network Security Services (NSS) 3.7.7
* Mozilla NSS_3_9_2_RTM:
ftp://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_9_2_ RTM/
Mozilla Network Security Services (NSS) 3.8
* Mozilla NSS_3_9_2_RTM:
ftp://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_9_2_ RTM/
Mozilla Network Security Services (NSS) 3.9
* Mozilla NSS_3_9_2_RTM:
ftp://ftp.mozilla.org/pub/mozilla.org/security/nss/releases/NSS_3_9_2_ RTM/
Sun Java System Application Server 7.0 Platform Edition
* Sun Sun Java System Application Server 7 2004Q2 Update 1:
* Sun Sun Java System Application Server Platform Edition 7 Update 5:
Telemetry
Coverage
IPS (Regular DB) | |
IPS (Extended DB) |
Version Updates
Date | Version | Detail |
---|---|---|
2021-04-28 | 18.069 | Sig Added |