Allaire JRun 3.0 Directory Disclosure Vulnerability
BID:1830
Info
Allaire JRun 3.0 Directory Disclosure Vulnerability
| Bugtraq ID: | 1830 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 23 2000 12:00AM |
| Updated: | Oct 23 2000 12:00AM |
| Credit: | Discovered and posted in a Foundstone Labs <[email protected]> Security Advisory on Oct 23, 2000. |
| Vulnerable: |
Macromedia JRun 3.1 Macromedia JRun 3.0 |
| Not Vulnerable: | |
Solution / Fix
Allaire JRun 3.0 Directory Disclosure Vulnerability
Solution:
The vendor has released patches which address this issue. Additional patches are also available which prevent exploitation of this issue via a raw HTTP GET request.
Macromedia JRun 3.0
Macromedia JRun 3.1
Solution:
The vendor has released patches which address this issue. Additional patches are also available which prevent exploitation of this issue via a raw HTTP GET request.
Macromedia JRun 3.0
-
Allaire extraslashes
Windows 95/98/NT/2000 and Windows NT Alpha
http://download.allaire.com/jrun/jrun3.0/extraslashes.ZIP -
Allaire extraslashes.tar
UNIX/Linux patch - GNU gzip/tar
http://download.allaire.com/jrun/jrun3.0/extraslashes.tar.gz -
Macromedia JRun Win32 jr30sp2_25232.exe
http://download.allaire.com/publicdl/en/jrun/30/jr30sp2_25232.exe -
Macromedia JRun Unix jr30sp2u_25232.sh
http://download.allaire.com/publicdl/en/jrun/30/jr30sp2u_25232.sh
Macromedia JRun 3.1
-
Macromedia JRun Win32 jrun-31-win-upgrade-us_26414.exe
http://download.allaire.com/publicdl/en/jrun/31/jrun-31-win-upgrade-us _26414.exe -
Macromedia JRun Unix jrun-31-unix-upgrade-us_26414.sh
http://download.allaire.com/publicdl/en/jrun/31/jrun-31-unix-upgrade-u s_26414.sh
References
Allaire JRun 3.0 Directory Disclosure Vulnerability
References:
References:
- JRun Product Homepage (Allaire)
- Macromedia Product Security Bulletin (MPSB01-16) (Macromedia)