Sun JSSE SSL/TLS Handshake Processing Denial Of Service Vulnerability

BID:24846

Info

Sun JSSE SSL/TLS Handshake Processing Denial Of Service Vulnerability

Bugtraq ID: 24846
Class: Design Error
CVE: CVE-2007-3698
Remote: Yes
Local: No
Published: Jul 10 2007 12:00AM
Updated: Mar 19 2015 08:44AM
Credit: The vendor disclosed this issue.
Vulnerable: SuSE SUSE Linux Enterprise Server 9
SuSE SUSE Linux Enterprise Server 10 SP1
SuSE SUSE Linux Enterprise SDK 10.SP1
SuSE SUSE Linux Enterprise Desktop 10 SP1
Sun SDK (Windows Production Release) 1.4.2 _15
Sun SDK (Windows Production Release) 1.4.2_14
Sun SDK (Windows Production Release) 1.4.2_13
Sun SDK (Windows Production Release) 1.4.2_12
Sun SDK (Windows Production Release) 1.4.2_11
Sun SDK (Solaris Production Release) 1.4.2 _15
Sun SDK (Solaris Production Release) 1.4.2_14
Sun SDK (Solaris Production Release) 1.4.2_13
Sun SDK (Solaris Production Release) 1.4.2_12
Sun SDK (Solaris Production Release) 1.4.2_11
Sun SDK (Linux Production Release) 1.4.2 _15
Sun SDK (Linux Production Release) 1.4.2
Sun SDK (Linux Production Release) 1.4.2_14
Sun SDK (Linux Production Release) 1.4.2_13
Sun SDK (Linux Production Release) 1.4.2_12
Sun SDK (Linux Production Release) 1.4.2_11
Sun JRE (Windows Production Release) 1.4.2_15
Sun JRE (Windows Production Release) 1.4.2_14
Sun JRE (Windows Production Release) 1.4.2_13
Sun JRE (Windows Production Release) 1.4.2_12
Sun JRE (Windows Production Release) 1.4.2_11
Sun JRE (Solaris Production Release) 1.4.2_15
Sun JRE (Solaris Production Release) 1.4.2_14
Sun JRE (Solaris Production Release) 1.4.2_13
Sun JRE (Solaris Production Release) 1.4.2_12
Sun JRE (Solaris Production Release) 1.4.2_11
Sun JRE (Linux Production Release) 1.4.2 _10
Sun JRE (Linux Production Release) 1.6.0_02
Sun JRE (Linux Production Release) 1.4.2_15
Sun JRE (Linux Production Release) 1.4.2_14
Sun JRE (Linux Production Release) 1.4.2_13
Sun JRE (Linux Production Release) 1.4.2_11
Sun JDK (Windows Production Release) 1.6.0_01
Sun JDK (Linux Production Release) 1.6 _01
Sun JDK (Linux Production Release) 1.5 0_10
Sun JDK (Linux Production Release) 1.5 _07
Sun JDK (Linux Production Release) 1.6.0_02
Sun JDK (Linux Production Release) 1.5.0.0_11
Sun JDK (Linux Production Release) 1.5.0.0_09
Sun JDK (Linux Production Release) 1.5.0.0_08
Slackware Linux 10.2
Slackware Linux 10.1
Slackware Linux 10.0
Slackware Linux 9.1
Slackware Linux 9.0
Slackware Linux 8.1
Slackware Linux 12.0
Slackware Linux 11.0
S.u.S.E. Open-Enterprise-Server 0
S.u.S.E. Novell Linux POS 9
S.u.S.E. CORE 9
RedHat Enterprise Linux Extras 4
RedHat Enterprise Linux Extras 3
Red Hat Enterprise Linux Supplementary 5 server
Red Hat Enterprise Linux Desktop Supplementary 5 client
HP OpenView Operations 8.0
HP OpenView Operations 7.1
HP OpenView Network Node Manager 7.53
HP OpenView Network Node Manager 7.51
HP OpenView Network Node Manager 7.01
Gentoo Linux
Cisco Unified Presence Server 6.0
Cisco Unified Presence Server 1.0(3)
Cisco Unified Presence Server 1.0(2)
Cisco Unified Presence Server 1.0
Cisco Unified CallManager 6.0
Cisco Unified CallManager 5.1
Cisco Unified CallManager 5.0(4a)SU1
Cisco Unified CallManager 5.0(4)
Cisco Unified CallManager 5.0(3a)
Cisco Unified CallManager 5.0(3)
Cisco Unified CallManager 5.0(2)
Cisco Unified CallManager 5.0(1)
Cisco Unified CallManager 5.0
BEA Systems JRockit 1.4.2
BEA Systems JRockit R27.3.1
BEA Systems JRockit 7.0
BEA Systems JRockit 6
BEA Systems JRockit 5.0
Apple Mac OS X Server 10.4.11
Apple Mac OS X Server 10.4.10
Apple Mac OS X 10.4.11
Apple Mac OS X 10.4.10
Not Vulnerable: Cisco Unified Presence Server 6.0(1)
Cisco Unified Communications Manager 6.0(1)
Cisco Unified Communications Manager 5.1(2)

Discussion

Sun JSSE SSL/TLS Handshake Processing Denial Of Service Vulnerability

The Sun JSSE (Java Secure Socket Extension) is prone to a denial-of-service vulnerability.

An attacker can exploit this issue to crash the computer, denying access to legitimate users.

Exploit / POC

Sun JSSE SSL/TLS Handshake Processing Denial Of Service Vulnerability

Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].

Solution / Fix

Sun JSSE SSL/TLS Handshake Processing Denial Of Service Vulnerability

Solution:
The vendor has released Sun Alert ID: 102997 and fixes to address this issue. Please see the references for more information.


Sun JRE (Linux Production Release) 1.4.2_11

Slackware Linux 12.0

Sun JRE (Linux Production Release) 1.4.2_14

Sun JRE (Solaris Production Release) 1.4.2_13

Sun SDK (Linux Production Release) 1.4.2_11

Sun SDK (Linux Production Release) 1.4.2_13

Sun SDK (Windows Production Release) 1.4.2_12

Sun SDK (Solaris Production Release) 1.4.2_13

BEA Systems JRockit R27.3.1

Sun JRE (Windows Production Release) 1.4.2_14

Sun SDK (Linux Production Release) 1.4.2_14

Sun JDK (Windows Production Release) 1.6.0_01

Sun JRE (Linux Production Release) 1.4.2_13

Sun JRE (Windows Production Release) 1.4.2_11

Sun SDK (Windows Production Release) 1.4.2_13

Sun JRE (Solaris Production Release) 1.4.2_11

Sun SDK (Windows Production Release) 1.4.2_14

Sun JRE (Windows Production Release) 1.4.2_13

Sun JRE (Solaris Production Release) 1.4.2_14

Sun SDK (Windows Production Release) 1.4.2_11

Sun JRE (Windows Production Release) 1.4.2_12

Sun SDK (Solaris Production Release) 1.4.2_14

Sun SDK (Solaris Production Release) 1.4.2_12

Sun JRE (Solaris Production Release) 1.4.2_12

BEA Systems JRockit 6

Sun SDK (Solaris Production Release) 1.4.2_11

Sun SDK (Linux Production Release) 1.4.2_12

BEA Systems JRockit 5.0

Sun JDK (Linux Production Release) 1.6 _01

Slackware Linux 10.0

Slackware Linux 10.1

Slackware Linux 10.2

Apple Mac OS X 10.4.10

Apple Mac OS X Server 10.4.10

Apple Mac OS X 10.4.11

Apple Mac OS X Server 10.4.11

Slackware Linux 8.1

Slackware Linux 9.0

Slackware Linux 9.1

References

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report