CVE-2005-3269
Summary
| CVE | CVE-2005-3269 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2005-10-20 23:02:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Stack-based buffer overflow in help.cgi in the HTTP administrative interface for (1) Sun Java System Directory Server 5.2 2003Q4, 2004Q2, and 2005Q1, (2) Red Hat Directory Server and (3) Certificate Server before 7.1 SP1, (4) Sun ONE Directory Server 5.1 SP4 and earlier, and (5) Sun ONE Administration Server 5.2 allows remote attackers to cause a denial of service (admin server crash), or local users to gain root privileges. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sun | Java System Directory Proxy Server | 5.2 | 2003q4 | All | All |
| Application | Sun | Java System Directory Proxy Server | 5.2 | 2004q2 | All | All |
| Application | Sun | Java System Directory Proxy Server | 5.2 | 2005q1 | All | All |
| Application | Sun | Java System Directory Server | 5.2 | All | All | All |
| Application | Sun | Java System Directory Server | 5.2 | 2003q4 | All | All |
| Application | Sun | Java System Directory Server | 5.2 | 2004q2 | All | All |
| Application | Sun | Java System Directory Server | 5.2 | 2005q1 | All | All |
| Application | Sun | One Administration Server | 5.2 | All | All | All |
| Application | Sun | One Directory Server | 4.16 | All | All | All |
| Application | Sun | One Directory Server | 4.16 | sp1 | All | All |
| Application | Sun | One Directory Server | 5.0 | All | All | All |
| Application | Sun | One Directory Server | 5.0 | sp1 | All | All |
| Application | Sun | One Directory Server | 5.0_sp2 | All | All | All |
| Application | Sun | One Directory Server | 5.1 | All | All | All |
| Application | Sun | One Directory Server | 5.1 | All | x86 | All |
| Application | Sun | One Directory Server | 5.1 | sp1 | All | All |
| Application | Sun | One Directory Server | 5.1 | sp2 | All | All |
| Application | Sun | One Directory Server | 5.1 | sp3 | All | All |
| Application | Sun | One Directory Server | 5.1 | sp3 | x86 | All |
| Application | Sun | One Directory Server | 5.1 | sp4 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| sunsolve.sun.com/search/document.do | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | |
| sunsolve.sun.com/search/document.do | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | |
| 'High Risk Vulnerability in Sun Directory Server' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| SecurityTracker.com Archives - Sun Directory Server Unspecified Bug Lets Remote Users Compromise the System | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| SecurityTracker.com Archives - Sun Directory Server Buffer Overflow in Help System May Let Remote Users Execute Arbitrary Code | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| #117665-03: Sun Java(TM) System Directory Server 5.2 patch 4 : Solaris patchzip | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | Patch |
| Secunia - Advisories - Sun Java System Directory Server HTTP Admin Interface Unspecified Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| SecurityTracker.com Archives - Red Hat Certificate Server Buffer Overflow in Help System May Let Remote Users Execute Arbitrary Code | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| Secunia - Advisories - Red Hat Directory Server / Certificate Server Buffer Overflow | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| SecurityTracker.com Archives - Red Hat Directory Server Buffer Overflow in Help System May Let Remote Users Execute Arbitrary Code | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Vendor Advisory |
| High Risk Vulnerability in Red Hat Directory Server and Red Hat Certificate Server - CXSecurity.com | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Sun ONE Directory Server Unspecified Remote Arbitrary Command Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| 'High Risk Vulnerability in Red Hat Directory Server and Red Hat Certificate Server' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| Red Hat Directory Server / Certificate Server Management Console Buffer Overflow Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| High Risk Vulnerability in Sun Directory Server - CXSecurity.com | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.