Security Vulnerabilities May Allow a Denial of Service in Sun Java System Web and Application Server Products



Category :Security
Release Phase :Resolved
Product :Sun Java System Application Server Standard Edition 7 2004Q2 Update 4
Sun Java System Web Server 6.1
Sun Java System Application Server Enterprise Edition 7 2004Q2
Sun Java System Application Server Enterprise Edition 7 2004Q2 Update 4
Sun ONE Web Server 6.0  
Bug Id :5004563, 5004542, 5016209  
Date of Resolved Release :02-NOV-2004 


Impact

A remote unprivileged user may be able to crash a Sun Java System Web Server or a Sun Java System Application Server which is configured to use SSL. Being able to crash an application is a type of Denial of Service (DoS).


Contributing Factors

These issues can occur in the following releases for all platforms:

  • Sun Java System Web Server 6.0 Service Pack 7 and earlier
  • Sun Java System Web Server 6.1 Service Pack 1 and earlier
  • Sun Java System Application Server 7 Standard Edition Update 4 and earlier
  • Sun Java System Application Server 7 Platform Edition Update 4 and earlier
  • Sun Java System Application Server 7 2004Q2

Symptoms

The server exits unexpectedly.


Workaround

There is no workaround. Please see the "Resolution" section below.


Resolution

These issues are addressed in the following releases:

  • Sun Java System Web Server 6.0 Service Pack 8 or later
  • Sun Java System Web Server 6.1 Service Pack 2 or later
  • Sun Java System Application Server 7 Standard Edition Update 5 or later
  • Sun Java System Application Server 7 Platform Edition Update 5 or later
  • Sun Java System Application Server 7 2004Q2 Update 1 or later

Sun Java System Web Server 6.0 SP 8 is available for download at http://wwws.sun.com/software/download/products/40968fe6.html.

Sun Java System Web Server 6.1 SP 3 is available for download at http://wwws.sun.com/software/download/products/415a094d.html.

Sun Java System Application Server 7 Standard Edition Update 5 is available for download at http://wwws.sun.com/software/download/products/414b472d.html.

Sun Java System Application Server Platform Edition 7 Update 5 is available for download at http://wwws.sun.com/software/download/products/4151fe59.html.

Sun Java System Application Server 7 2004Q2 Update 1 is available for download at http://wwws.sun.com/software/download/products/4154c5a5.html.




Modification History


Date: 22-DEC-2005

22-Dec-2005:

  • Update Impact section



Attachments
This solution has no attachment

 
 
Login Required

You must login and have a valid contract to access Sun's Premium content which includes:

  • Sun Alerts
  • Bugs
  • Patches
  • Solutions
  • White Papers
  • Documentation
  • Support Knowledge

Login Required

You must login and have a valid contract to access Sun's contracted features

Access Legend:

(Login to access)   Sun Contracted Content
(Login to access)   Sun Contracted Feature

Please make use of SunSolve Feedback application by selecting the floating [+] to provide feedback about this specific document.

Search

Article Details
Article ID : 201567
Article Type : Sun Alert
Last reviewed : 2006-04-14
Audience : PUBLIC
Keywords :
Provide feedback  (help)
Page Tools
»  Print This Page
»  Email This Article
»  Bookmark This Article