JanaServer 2 Multiple Remote Denial Of Service Vulnerabilities
BID:11780
Info
JanaServer 2 Multiple Remote Denial Of Service Vulnerabilities
| Bugtraq ID: | 11780 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 30 2004 12:00AM |
| Updated: | Nov 30 2004 12:00AM |
| Credit: | Luigi Auriemma <[email protected]> is credited with the discovery of this issue. |
| Vulnerable: |
Jana Server JanaServer 2 2.4.4 Jana Server JanaServer 2 2.4.3 Jana Server JanaServer 2 2.4.2 Jana Server JanaServer 2 2.4.1 Jana Server JanaServer 2 2.4.0 |
| Not Vulnerable: |
Jana Server JanaServer 2 2.4.5.1 Jana Server JanaServer 2 2.4.5 |
Discussion
JanaServer 2 Multiple Remote Denial Of Service Vulnerabilities
JanaServer 2 is a commercially available proxy server designed for the Microsoft Windows platform. It contains support for services such as HTTP, FTP, email, and RealPlayer streaming.
Multiple remote denial of service vulnerabilities affect JanaServer 2. These issues are due to a failure of the application to handle malformed network communications.
The first issue presents itself when malformed HTTP requests are made to the affected application. The second issue presents itself when the application attempts to process malformed RealPlayer streaming data.
An attacker may leverage these issues to cause the affected proxy server to hang, effectively denying service to legitimate users.
JanaServer 2 is a commercially available proxy server designed for the Microsoft Windows platform. It contains support for services such as HTTP, FTP, email, and RealPlayer streaming.
Multiple remote denial of service vulnerabilities affect JanaServer 2. These issues are due to a failure of the application to handle malformed network communications.
The first issue presents itself when malformed HTTP requests are made to the affected application. The second issue presents itself when the application attempts to process malformed RealPlayer streaming data.
An attacker may leverage these issues to cause the affected proxy server to hang, effectively denying service to legitimate users.
Exploit / POC
JanaServer 2 Multiple Remote Denial Of Service Vulnerabilities
The following exploit has been provided:
The following exploit has been provided:
Solution / Fix
JanaServer 2 Multiple Remote Denial Of Service Vulnerabilities
Solution:
The vendor has released an upgrade dealing with these issues.
Jana Server JanaServer 2 2.4.4
Jana Server JanaServer 2 2.4.0
Jana Server JanaServer 2 2.4.3
Jana Server JanaServer 2 2.4.1
Jana Server JanaServer 2 2.4.2
Solution:
The vendor has released an upgrade dealing with these issues.
Jana Server JanaServer 2 2.4.4
-
JanaServer JanaServer 2.4.5.1
http://www.janaserver.de/start.php?lang=en&menue=download&content=down
Jana Server JanaServer 2 2.4.0
-
JanaServer JanaServer 2.4.5.1
http://www.janaserver.de/start.php?lang=en&menue=download&content=down
Jana Server JanaServer 2 2.4.3
-
JanaServer JanaServer 2.4.5.1
http://www.janaserver.de/start.php?lang=en&menue=download&content=down
Jana Server JanaServer 2 2.4.1
-
JanaServer JanaServer 2.4.5.1
http://www.janaserver.de/start.php?lang=en&menue=download&content=down
Jana Server JanaServer 2 2.4.2
-
JanaServer JanaServer 2.4.5.1
http://www.janaserver.de/start.php?lang=en&menue=download&content=down
References
JanaServer 2 Multiple Remote Denial Of Service Vulnerabilities
References:
References:
- JanaServer 2 Home Page (JanaServer)
- JanaServer Version History (JanaServer)
- Endless loops in the http-server and pna-proxy modules of Jana server 2.4.4 (Luigi Auriemma
)