Oracle WebLogic Server Apache Connector Stack Based Buffer Overflow Vulnerability
BID:31761
Info
Oracle WebLogic Server Apache Connector Stack Based Buffer Overflow Vulnerability
| Bugtraq ID: | 31761 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-0019 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 14 2008 12:00AM |
| Updated: | Oct 16 2008 03:37PM |
| Credit: | Chris Valasek of the IBM X-Force |
| Vulnerable: |
BEA Systems Weblogic Server Apache plug-in |
| Not Vulnerable: | |
Discussion
Oracle WebLogic Server Apache Connector Stack Based Buffer Overflow Vulnerability
Oracle WebLogic Server Apache Connector is prone to a stack-based buffer-overflow vulnerability because the application fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer.
An attacker can exploit this issue to execute arbitrary code in the context of the application. Failed exploit attempts will likely result in a denial-of-service condition.
Oracle WebLogic Server Apache Connector is prone to a stack-based buffer-overflow vulnerability because the application fails to bounds-check user-supplied data before copying it into an insufficiently sized buffer.
An attacker can exploit this issue to execute arbitrary code in the context of the application. Failed exploit attempts will likely result in a denial-of-service condition.
Exploit / POC
Oracle WebLogic Server Apache Connector Stack Based Buffer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Oracle WebLogic Server Apache Connector Stack Based Buffer Overflow Vulnerability
Solution:
Reportedly, the vendor has fixed the issue, but Symantec has not confirmed this. Please see the references for more information.
Solution:
Reportedly, the vendor has fixed the issue, but Symantec has not confirmed this. Please see the references for more information.
References
Oracle WebLogic Server Apache Connector Stack Based Buffer Overflow Vulnerability
References:
References:
- Oracle WebLogic Server Apache Connector Remote Code Execution (IBM Internet Security Systems)
- WebLogic Server Product Homepage (Oracle)