HP VirtualVault Netscape Enterprise Server Vulnerability
BID:259
Info
HP VirtualVault Netscape Enterprise Server Vulnerability
| Bugtraq ID: | 259 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 14 1999 12:00AM |
| Updated: | May 14 1999 12:00AM |
| Credit: | This vulnerability was reported to the BUGTRAQ mailing list by John Daniele <[email protected]>. |
| Vulnerable: |
HP VirtualVault 3.50 HP VirtualVault 3.1 HP VirtualVault 3.0 |
| Not Vulnerable: | |
Discussion
HP VirtualVault Netscape Enterprise Server Vulnerability
HP's VirtualVault is a trusted web server platform that implements compartmentalization. The bundled web server is a version of the Netscape Enterprise Server. A vulnerability in the NES makes it vulnerable to a denial of service.
If a CGI request longer than 512 bytes in length made (e.g. "GET /cgi-bin/somecgi.cgi?AAAAAAAAA...") the Netscape Enterprise Server will be unable to service any further CGI requests.
The affected filesets are VaultNES.NES-VAULT and VaultTS.INES-COMMON.
HP's VirtualVault is a trusted web server platform that implements compartmentalization. The bundled web server is a version of the Netscape Enterprise Server. A vulnerability in the NES makes it vulnerable to a denial of service.
If a CGI request longer than 512 bytes in length made (e.g. "GET /cgi-bin/somecgi.cgi?AAAAAAAAA...") the Netscape Enterprise Server will be unable to service any further CGI requests.
The affected filesets are VaultNES.NES-VAULT and VaultTS.INES-COMMON.
Exploit / POC
HP VirtualVault Netscape Enterprise Server Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
HP VirtualVault Netscape Enterprise Server Vulnerability
Solution:
A temporary solution is to comment out the "vault-auth-log" AddLog line from the NES's obj.conf file.
To fix apply the appropriate patches to correct the problem:
HP-UX 10.24 with VirtualVault A.02.00 US/Canada
HP-UX 10.24 with VirtualVault A.02.00 International:
PHCO_18615
PHSS_18620
HP-UX 10.24 with VirtualVault A.03.00 US/Canada
HP-UX 10.24 with VirtualVault A.03.00 International:
PHCO_18615
PHSS_18616
HP-UX 10.24 with VirtualVault A.03.01 US/Canada
HP-UX 10.24 with VirtualVault A.03.01 International:
PHCO_18615
PHSS_18612
HP-UX 10.24 with VirtualVault A.03.50 US/Canada
HP-UX 10.24 with VirtualVault A.03.50 International
PHCO_18615
PHSS_18621
Solution:
A temporary solution is to comment out the "vault-auth-log" AddLog line from the NES's obj.conf file.
To fix apply the appropriate patches to correct the problem:
HP-UX 10.24 with VirtualVault A.02.00 US/Canada
HP-UX 10.24 with VirtualVault A.02.00 International:
PHCO_18615
PHSS_18620
HP-UX 10.24 with VirtualVault A.03.00 US/Canada
HP-UX 10.24 with VirtualVault A.03.00 International:
PHCO_18615
PHSS_18616
HP-UX 10.24 with VirtualVault A.03.01 US/Canada
HP-UX 10.24 with VirtualVault A.03.01 International:
PHCO_18615
PHSS_18612
HP-UX 10.24 with VirtualVault A.03.50 US/Canada
HP-UX 10.24 with VirtualVault A.03.50 International
PHCO_18615
PHSS_18621
References
HP VirtualVault Netscape Enterprise Server Vulnerability
References:
References: