Multiple Vendor XML Parser Denial Of Service Vulnerability
BID:6398
Info
Multiple Vendor XML Parser Denial Of Service Vulnerability
| Bugtraq ID: | 6398 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 16 2002 12:00AM |
| Updated: | Dec 16 2002 12:00AM |
| Credit: | Discovery of this vulnerability credited to Amit Klein <[email protected]>. |
| Vulnerable: |
The Expat Developers Expat 1.95.4 The Expat Developers Expat 1.95.2 The Expat Developers Expat 1.95.1 Sybase Enterprise Application Server 4.1.3 Sybase Enterprise Application Server 4.1.2 Sybase Enterprise Application Server 4.1.1 Sybase Enterprise Application Server 4.1 Sun ONE Web Server 6.0 SP5 Sun ONE Web Server 6.0 SP4 Sun ONE Web Server 6.0 SP3 Sun ONE Web Server 6.0 SP2 Sun ONE Web Server 6.0 SP1 Sun ONE Web Server 6.0 Sun ONE Web Server 4.1 SP11 Sun ONE Web Server 4.1 SP10 Sun ONE Web Server 4.1 IBM Websphere Application Server 4.0.3 IBM Websphere Application Server 3.5.3 IBM Websphere Application Server 3.5.2 IBM Websphere Application Server 3.5.1 IBM Websphere Application Server 3.5 IBM Websphere Application Server 3.0.2 .1 IBM Websphere Application Server 3.0.2 IBM Websphere Application Server 3.0 .2.4 IBM Websphere Application Server 3.0 .2.3 IBM Websphere Application Server 3.0 .2.2 IBM Websphere Application Server 3.0 IBM Websphere Application Server 2.0 Apache Xerces2 Java Parser 2.2.1 Apache Xerces2 Java Parser 2.2 .0 Apache Xerces2 Java Parser 2.1 .0 Apache Xerces2 Java Parser 2.0.2 Apache Xerces Perl 1.7 .0-1 Apache Xerces C++ 2.1 .0 Apache Axis 1.1 beta Apache Axis 1.0 |
| Not Vulnerable: | |
Discussion
Multiple Vendor XML Parser Denial Of Service Vulnerability
A denial of service vulnerability occurs in the XML parser, either Crimson or Xerces, used by several vendors.
An attacker can exploit this vulnerability by sending a specially crafted message to the SOAP interface used by the vulnerable software. When the XML parser receives this message, it will consume all available CPU resources. This will cause the system to become unresponsive to further requests for service thereby resulting in a denial of service condition.
This vulnerability has been previously described in BIDs 6363 and 6378 for Macromedia JRun and BEA Systems WebLogic.
A denial of service vulnerability occurs in the XML parser, either Crimson or Xerces, used by several vendors.
An attacker can exploit this vulnerability by sending a specially crafted message to the SOAP interface used by the vulnerable software. When the XML parser receives this message, it will consume all available CPU resources. This will cause the system to become unresponsive to further requests for service thereby resulting in a denial of service condition.
This vulnerability has been previously described in BIDs 6363 and 6378 for Macromedia JRun and BEA Systems WebLogic.
Exploit / POC
Multiple Vendor XML Parser Denial Of Service Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Multiple Vendor XML Parser Denial Of Service Vulnerability
Solution:
Sybase EAServer users are advised to download the appropriate EBFs from the referenced Web site.
HP is investigating this issue and will be providing fixes for any affected platforms and software.
Macromedia has released fixes for JRun and ColdFusion MX. See BID 6363 for information about obtaining Macromedia fixes.
BEA Systems has released fixes for WebLogic. See BID 6378 for information about obtaining WebLogic fixes.
Solution:
Sybase EAServer users are advised to download the appropriate EBFs from the referenced Web site.
HP is investigating this issue and will be providing fixes for any affected platforms and software.
Macromedia has released fixes for JRun and ColdFusion MX. See BID 6363 for information about obtaining Macromedia fixes.
BEA Systems has released fixes for WebLogic. See BID 6378 for information about obtaining WebLogic fixes.