Macromedia JRun Session ID Cookie HTTP Response Splitting Vulnerability
BID:11413
Info
Macromedia JRun Session ID Cookie HTTP Response Splitting Vulnerability
| Bugtraq ID: | 11413 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 14 2004 12:00AM |
| Updated: | Oct 14 2004 12:00AM |
| Credit: | The individual responsible for the discovery of this issue is currently unknown; "ACROS Security" <[email protected]> is credited with its disclosure. |
| Vulnerable: |
Macromedia JRun 4.0 SP1a Macromedia JRun 4.0 SP1 Macromedia JRun 4.0 build 61650 Macromedia JRun 4.0 |
| Not Vulnerable: | |
Discussion
Macromedia JRun Session ID Cookie HTTP Response Splitting Vulnerability
An HTTP response splitting vulnerability affects Macromedia JRun due to Session ID handling. This issue is due to a failure of the application to properly handle how POST requests are processed.
A remote attacker may exploit this vulnerability to influence or misrepresent how web content is served, cached or interpreted. This could aid in various attacks, which try to entice client users into a false sense of trust.
An HTTP response splitting vulnerability affects Macromedia JRun due to Session ID handling. This issue is due to a failure of the application to properly handle how POST requests are processed.
A remote attacker may exploit this vulnerability to influence or misrepresent how web content is served, cached or interpreted. This could aid in various attacks, which try to entice client users into a false sense of trust.
Exploit / POC
Macromedia JRun Session ID Cookie HTTP Response Splitting Vulnerability
No exploit is required to leverage this issue.
No exploit is required to leverage this issue.
Solution / Fix
Macromedia JRun Session ID Cookie HTTP Response Splitting Vulnerability
Solution:
This issue was addressed by Macromedia Security Bulletin MPSB04-08. Fixes may be applied with the JRun Update 4 tool that is available from the JRun Support Center.
Solution:
This issue was addressed by Macromedia Security Bulletin MPSB04-08. Fixes may be applied with the JRun Update 4 tool that is available from the JRun Support Center.
References
Macromedia JRun Session ID Cookie HTTP Response Splitting Vulnerability
References:
References:
- Macromedia JRun Support Center - Updaters (Macromedia)
- MPSB04-08 - Cumulative Security Patch available for JRun server (Macromedia)
- ACROS Security: Unsanitized Session ID Cookie Allows Modifying Server Response ("ACROS Security"
)