Sun Java System Directory Server LDAP Search Request Denial of Service Vulnerability
BID:37899
Info
Sun Java System Directory Server LDAP Search Request Denial of Service Vulnerability
| Bugtraq ID: | 37899 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 20 2010 12:00AM |
| Updated: | Mar 01 2010 08:02PM |
| Credit: | Sun |
| Vulnerable: |
Sun Java System Directory Server Enterprise Edition 6.3.1 Sun Java System Directory Server Enterprise Edition 7.0 Sun Java System Directory Server Enterprise Edition 6.3 Sun Java System Directory Server Enterprise Edition 6.2 Sun Java System Directory Server Enterprise Edition 6.1 Sun Java System Directory Server Enterprise Edition 6.0 Sun Java System Directory Server 5.2 |
| Not Vulnerable: | |
Discussion
Sun Java System Directory Server LDAP Search Request Denial of Service Vulnerability
Sun Java System Directory Server is prone to a denial-of-service vulnerability.
An attacker can exploit this issue to crash the effected application, denying service to legitimate users.
The following products are affected:
Sun Directory Server Enterprise Edition 7.0
Sun Java System Directory Server Enterprise Edition 6.3.1
Sun Java System Directory Server Enterprise Edition 6.3
Sun Java System Directory Server Enterprise Edition 6.2
Sun Java System Directory Server Enterprise Edition 6.1
Sun Java System Directory Server Enterprise Edition 6.0
Sun Java System Directory Server 5.2
NOTE: This issue may be related to the issue described in BID 37699 (Sun Java System Directory Server 'core_get_proxyauth_dn' Denial of Service Vulnerability). We will update this BID when more information emerges.
Sun Java System Directory Server is prone to a denial-of-service vulnerability.
An attacker can exploit this issue to crash the effected application, denying service to legitimate users.
The following products are affected:
Sun Directory Server Enterprise Edition 7.0
Sun Java System Directory Server Enterprise Edition 6.3.1
Sun Java System Directory Server Enterprise Edition 6.3
Sun Java System Directory Server Enterprise Edition 6.2
Sun Java System Directory Server Enterprise Edition 6.1
Sun Java System Directory Server Enterprise Edition 6.0
Sun Java System Directory Server 5.2
NOTE: This issue may be related to the issue described in BID 37699 (Sun Java System Directory Server 'core_get_proxyauth_dn' Denial of Service Vulnerability). We will update this BID when more information emerges.
Exploit / POC
Sun Java System Directory Server LDAP Search Request Denial of Service Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Sun Java System Directory Server LDAP Search Request Denial of Service Vulnerability
References:
References: