Macromedia JRun Multiple Remote Vulnerabilities
BID:11245
Info
Macromedia JRun Multiple Remote Vulnerabilities
| Bugtraq ID: | 11245 |
| Class: | Design Error |
| CVE: |
CVE-2004-0646 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 24 2004 12:00AM |
| Updated: | Jul 12 2009 07:06AM |
| Credit: | iDEFENSE, @Stake, and Acros are credited for the discovery of these vulnerabilities. |
| Vulnerable: |
Macromedia JRun 4.0 Macromedia JRun 3.1 Macromedia JRun 3.0 Macromedia ColdFusion MX J2EE 6.1 Macromedia ColdFusion MX 6.1 Macromedia ColdFusion MX 6.0 Hitachi Cosminexus Server Web Edition 01-02 (*2) Hitachi Cosminexus Server Web Edition 01-01 (*1) Hitachi Cosminexus Enterprise Standard Edition 01-02 (*2) Hitachi Cosminexus Enterprise Standard Edition 01-01 (*1) Hitachi Cosminexus Enterprise Enterprise Edition 01-02 (*2) Hitachi Cosminexus Enterprise Enterprise Edition 01-01 (*1) |
| Not Vulnerable: | |
Discussion
Macromedia JRun Multiple Remote Vulnerabilities
Multiple vulnerabilities are reported in Macromedia JRun.
The first vulnerability is reported to exist in an insecure implementation of a session variable, 'JSESSIONID'. This vulnerability allows remote attackers to bypass authentication checks, and may possibly allow them to gain administrative access to the web application.
The second issue is a source code disclosure vulnerability. This vulnerability allows attackers to retrieve the contents of potentially sensitive script files. This may aid them in further attacks.
The third issue is a buffer overflow vulnerability allowing remote attackers to reportedly crash affected servers.
Versions 3.0, 3.1, and 4.0 are reportedly affected by these vulnerabilities.
Multiple vulnerabilities are reported in Macromedia JRun.
The first vulnerability is reported to exist in an insecure implementation of a session variable, 'JSESSIONID'. This vulnerability allows remote attackers to bypass authentication checks, and may possibly allow them to gain administrative access to the web application.
The second issue is a source code disclosure vulnerability. This vulnerability allows attackers to retrieve the contents of potentially sensitive script files. This may aid them in further attacks.
The third issue is a buffer overflow vulnerability allowing remote attackers to reportedly crash affected servers.
Versions 3.0, 3.1, and 4.0 are reportedly affected by these vulnerabilities.
Exploit / POC
Macromedia JRun Multiple Remote Vulnerabilities
Currently we are not aware of any exploits for the buffer overflow issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
The other vulnerabilities do not require an exploit.
Currently we are not aware of any exploits for the buffer overflow issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
The other vulnerabilities do not require an exploit.
Solution / Fix
Macromedia JRun Multiple Remote Vulnerabilities
Solution:
The vendor has released advisories for affected products along with fixes to address these issues. Please see the referenced advisories for further information.
Hitachi has released a security advisory (HS04-008) dealing with this issue for their Cosminexus Web Contents Generator. They have advised that users disable the 'verbose' setting of the affected JRun implementation, or that they apply the Macromedia patch. Please see the referenced web advisory for more information.
Macromedia JRun 3.0
Macromedia JRun 3.1
Macromedia ColdFusion MX 6.0
Macromedia ColdFusion MX J2EE 6.1
Macromedia ColdFusion MX 6.1
Solution:
The vendor has released advisories for affected products along with fixes to address these issues. Please see the referenced advisories for further information.
Hitachi has released a security advisory (HS04-008) dealing with this issue for their Cosminexus Web Contents Generator. They have advised that users disable the 'verbose' setting of the affected JRun implementation, or that they apply the Macromedia patch. Please see the referenced web advisory for more information.
Macromedia JRun 3.0
-
Macromedia JRun 3.0 Linux/Unix 79805
http://download.macromedia.com/pub/ -
Macromedia JRun 3.0 Windows 79805
http://download.macromedia.com/pub/
Macromedia JRun 3.1
-
Macromedia JRun 3.1 Linux/Unix 79805
http://download.macromedia.com/pub/ -
Macromedia JRun 3.1 Windows 79805
http://download.macromedia.com/pub/
Macromedia ColdFusion MX 6.0
-
Macromedia ColdFusion MX 6.0
ColdFusion MX 6.0
http://www.macromedia.com/cfusion/resourcecenter/rc_driver.cfm?pagenam e=cfmx%20updater
Macromedia ColdFusion MX J2EE 6.1
-
Macromedia ColdFusion MX 6.1 J2EE (JRun)
ColdFusion MX 6.1 J2EE (JRun)
http://www.macromedia.com/go/jrun_updater
Macromedia ColdFusion MX 6.1
-
Macromedia ColdFusion MX 6.1 Standard/Enterprise
ColdFusion MX 6.1 Standard/Enterprise
http://www.macromedia.com/support/coldfusion/downloads_updates.html#up dater
References
Macromedia JRun Multiple Remote Vulnerabilities
References:
References:
- HS04-008 - Vulnerability of Buffer Overflow in Macromedia JRun (Hitachi)
- JRun Homepage (Adobe)
- Macromedia Homepage (Macromedia)
- MPSB04-08 - Cumulative Security Patch available for JRun server (Macromedia)
- MPSB04-09 - Cumulative Security Patch available for ColdFusion MX (Macromedia)
- iDEFENSE Security Advisory 09.29.04 - Macromedia JRun 4 mod_jrun Apache Module B (iDEFENSE)