Netscape Enterprise Server Web Publisher DoS Vulnerability
BID:3826
Info
Netscape Enterprise Server Web Publisher DoS Vulnerability
| Bugtraq ID: | 3826 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 09 2002 12:00AM |
| Updated: | Jan 09 2002 12:00AM |
| Credit: | Discovered by Richard Brain and published in ProCheckUp Security Bulletin PR01-04. Published in CERT Vulnerability Note VU#191763. |
| Vulnerable: |
Netscape Enterprise Server 3.6 Netscape Enterprise Server 3.5 Netscape Enterprise Server 3.4 Netscape Enterprise Server 3.3 Netscape Enterprise Server 3.2 Netscape Enterprise Server 3.1 Netscape Enterprise Server 3.0 iPlanet E-Commerce Solutions iPlanet Web Server Enterprise Edition 4.1 iPlanet E-Commerce Solutions iPlanet Web Server Enterprise Edition 4.0 |
| Not Vulnerable: | |
Discussion
Netscape Enterprise Server Web Publisher DoS Vulnerability
Netscape Enterprise Server is a web server used to host larger-scale websites. A Web Publishing feature is installed by default. The Enterprise Server runs on Microsoft and most Unix and Linux platforms.
A denial of service condition has been reported when Web Publishing is enabled.
Submitting a malformed '?wp-html-rend' request to a host running the server, will achieve the denial of service condition.
It should be noted that this issue has only been known to work on Microsoft Windows NT or 2000 hosts. In addition, iPlanet Web Server Enterprise Edition is also vulnerable to this issue.
Netscape Enterprise Server is a web server used to host larger-scale websites. A Web Publishing feature is installed by default. The Enterprise Server runs on Microsoft and most Unix and Linux platforms.
A denial of service condition has been reported when Web Publishing is enabled.
Submitting a malformed '?wp-html-rend' request to a host running the server, will achieve the denial of service condition.
It should be noted that this issue has only been known to work on Microsoft Windows NT or 2000 hosts. In addition, iPlanet Web Server Enterprise Edition is also vulnerable to this issue.
Exploit / POC
Netscape Enterprise Server Web Publisher DoS Vulnerability
No exploit code is required.
No exploit code is required.
Solution / Fix
Netscape Enterprise Server Web Publisher DoS Vulnerability
Solution:
iPlanet has released the following files which will disable the wp-html-rend command:
Netscape Enterprise Server 3.0
Netscape Enterprise Server 3.1
Netscape Enterprise Server 3.2
Netscape Enterprise Server 3.3
Netscape Enterprise Server 3.4
Netscape Enterprise Server 3.5
Netscape Enterprise Server 3.6
iPlanet E-Commerce Solutions iPlanet Web Server Enterprise Edition 4.0
iPlanet E-Commerce Solutions iPlanet Web Server Enterprise Edition 4.1
Solution:
iPlanet has released the following files which will disable the wp-html-rend command:
Netscape Enterprise Server 3.0
-
iPlanet DisRend
http://knowledgebase.iplanet.com/NASApp/ikb/cat?file=file/7761/DisRend .c -
iPlanet disrend.dll
http://knowledgebase.iplanet.com/NASApp/ikb/cat?file=file/7761/disrend .dll
Netscape Enterprise Server 3.1
-
iPlanet DisRend
http://knowledgebase.iplanet.com/NASApp/ikb/cat?file=file/7761/DisRend .c -
iPlanet disrend.dll
http://knowledgebase.iplanet.com/NASApp/ikb/cat?file=file/7761/disrend .dll
Netscape Enterprise Server 3.2
-
iPlanet DisRend
http://knowledgebase.iplanet.com/NASApp/ikb/cat?file=file/7761/DisRend .c -
iPlanet disrend.dll
http://knowledgebase.iplanet.com/NASApp/ikb/cat?file=file/7761/disrend .dll
Netscape Enterprise Server 3.3
-
iPlanet DisRend
http://knowledgebase.iplanet.com/NASApp/ikb/cat?file=file/7761/DisRend .c -
iPlanet disrend.dll
http://knowledgebase.iplanet.com/NASApp/ikb/cat?file=file/7761/disrend .dll
Netscape Enterprise Server 3.4
-
iPlanet DisRend
http://knowledgebase.iplanet.com/NASApp/ikb/cat?file=file/7761/DisRend .c -
iPlanet disrend.dll
http://knowledgebase.iplanet.com/NASApp/ikb/cat?file=file/7761/disrend .dll
Netscape Enterprise Server 3.5
-
iPlanet DisRend
http://knowledgebase.iplanet.com/NASApp/ikb/cat?file=file/7761/DisRend .c -
iPlanet disrend.dll
http://knowledgebase.iplanet.com/NASApp/ikb/cat?file=file/7761/disrend .dll
Netscape Enterprise Server 3.6
-
iPlanet DisRend
http://knowledgebase.iplanet.com/NASApp/ikb/cat?file=file/7761/DisRend .c -
iPlanet disrend.dll
http://knowledgebase.iplanet.com/NASApp/ikb/cat?file=file/7761/disrend .dll
iPlanet E-Commerce Solutions iPlanet Web Server Enterprise Edition 4.0
-
iPlanet DisRend
http://knowledgebase.iplanet.com/NASApp/ikb/cat?file=file/7761/DisRend .c -
iPlanet disrend.dll
http://knowledgebase.iplanet.com/NASApp/ikb/cat?file=file/7761/disrend .dll
iPlanet E-Commerce Solutions iPlanet Web Server Enterprise Edition 4.1
-
iPlanet DisRend
http://knowledgebase.iplanet.com/NASApp/ikb/cat?file=file/7761/DisRend .c -
iPlanet disrend.dll
http://knowledgebase.iplanet.com/NASApp/ikb/cat?file=file/7761/disrend .dll
References
Netscape Enterprise Server Web Publisher DoS Vulnerability
References:
References:
- ?wp-html-rend causes access violation on Windows NT and 2000 (iPlanet)
- Security Bulletin PR01-04 (ProCheckUp)