T. Hauck Jana Server MS-DOS Device Name DoS Vulnerability
BID:2704
Info
T. Hauck Jana Server MS-DOS Device Name DoS Vulnerability
| Bugtraq ID: | 2704 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 07 2001 12:00AM |
| Updated: | May 07 2001 12:00AM |
| Credit: | Discovered and posted to Bugtraq by <[email protected]> on May 7, 2001. |
| Vulnerable: |
T. Hauck Jana Webserver 2.0 Beta1 T. Hauck Jana Webserver 1.46 T. Hauck Jana Webserver 1.45 |
| Not Vulnerable: |
T. Hauck Jana Webserver 2.0 Beta2 |
Discussion
T. Hauck Jana Server MS-DOS Device Name DoS Vulnerability
Versions of Jana Server are vulnerable to a denial of service attack.
It is possible to remotely crash a system running Jana Server by submitting a URL request which specifies an MS-DOS devicename.
A hard reboot of the exploited server will be required to restore web services.
Versions of Jana Server are vulnerable to a denial of service attack.
It is possible to remotely crash a system running Jana Server by submitting a URL request which specifies an MS-DOS devicename.
A hard reboot of the exploited server will be required to restore web services.
Exploit / POC
T. Hauck Jana Server MS-DOS Device Name DoS Vulnerability
www.example.com/aux
www.example.com/aux
Solution / Fix
T. Hauck Jana Server MS-DOS Device Name DoS Vulnerability
Solution:
Jana Server v2.0 Beta2 is not affected by this issue:
T. Hauck Jana Webserver 1.45
T. Hauck Jana Webserver 1.46
Solution:
Jana Server v2.0 Beta2 is not affected by this issue:
T. Hauck Jana Webserver 1.45
-
T. Hauck Jana2E
http://home.t-online.de/home/T.Hauck/Bin/Jana2E.zip
T. Hauck Jana Webserver 1.46
-
T. Hauck Jana2E
http://home.t-online.de/home/T.Hauck/Bin/Jana2E.zip
References
T. Hauck Jana Server MS-DOS Device Name DoS Vulnerability
References:
References:
- Jana Server Homepage (T. Hauck)