Sun ONE/iPlanet Web Server Chunked Encoding Vulnerability
BID:5433
Info
Sun ONE/iPlanet Web Server Chunked Encoding Vulnerability
| Bugtraq ID: | 5433 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 08 2002 12:00AM |
| Updated: | Aug 08 2002 12:00AM |
| Credit: | This vulnerability was discovered by Riley Hassell of eEye Digital Security. |
| Vulnerable: |
Sun ONE Web Server 6.0 SP3 Sun ONE Web Server 6.0 SP2 Sun ONE Web Server 6.0 SP1 Sun ONE Web Server 6.0 Sun iPlanet Web Server 4.1 SP9 Sun iPlanet Web Server 4.1 SP8 Sun iPlanet Web Server 4.1 SP7 Sun iPlanet Web Server 4.1 SP6 Sun iPlanet Web Server 4.1 SP5 Sun iPlanet Web Server 4.1 SP4 Sun iPlanet Web Server 4.1 SP3 Sun iPlanet Web Server 4.1 SP2 Sun iPlanet Web Server 4.1 SP1 Sun iPlanet Web Server 4.1 Sun iPlanet Web Server 4.0 |
| Not Vulnerable: |
Sun ONE Web Server 6.0 SP4 Sun ONE Web Server 4.1 SP11 |
Discussion
Sun ONE/iPlanet Web Server Chunked Encoding Vulnerability
When processing requests coded with the 'Chunked Encoding' mechanism, Sun ONE/iPlanet fails to properly calculate required buffer sizes. Consequently, several conditions may occur that have security implications. A remote attacker may craft a specially malformed session in order to overwrite the heap of the target system.
It has been reported that a buffer overrun may occur. Exploitation of these conditions may result in the execution of arbitrary code or a denial of service attack.
When processing requests coded with the 'Chunked Encoding' mechanism, Sun ONE/iPlanet fails to properly calculate required buffer sizes. Consequently, several conditions may occur that have security implications. A remote attacker may craft a specially malformed session in order to overwrite the heap of the target system.
It has been reported that a buffer overrun may occur. Exploitation of these conditions may result in the execution of arbitrary code or a denial of service attack.
Exploit / POC
Sun ONE/iPlanet Web Server Chunked Encoding Vulnerability
CORE has developed a working commercial exploit for their IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
CORE has developed a working commercial exploit for their IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
References
Sun ONE/iPlanet Web Server Chunked Encoding Vulnerability
References:
References:
- 46127 (Sun Microsystems)
- Sun™ ONE / iPlanet Web Server 4.1 and 6.0 Remote Buffer Overflow (eEye)
- Sun(TM) ONE Web Server Security Advisory: Buffer Overflow in Transfer Encoding (Sun)
- SunONE-iPlanet Web Server ChunkedEncoding exploit (CORE Security)