iPlanet Web Server Response Header Buffer Overflow Vulnerability
BID:6826
Info
iPlanet Web Server Response Header Buffer Overflow Vulnerability
| Bugtraq ID: | 6826 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 16 2001 12:00AM |
| Updated: | Apr 16 2001 12:00AM |
| Credit: | Discovery of this issue is credited to @stake. |
| Vulnerable: |
Sun iPlanet Web Server 4.1 SP6 Sun iPlanet Web Server 4.1 SP5 Sun iPlanet Web Server 4.1 SP4 Sun iPlanet Web Server 4.1 SP3 Sun iPlanet Web Server 4.1 SP2 Sun iPlanet Web Server 4.1 SP1 Sun iPlanet Web Server 4.1 iPlanet E-Commerce Solutions iPlanet Web Server Enterprise Edition 4.0 SP6 iPlanet E-Commerce Solutions iPlanet Web Server Enterprise Edition 4.0 SP5 iPlanet E-Commerce Solutions iPlanet Web Server Enterprise Edition 4.0 SP4 iPlanet E-Commerce Solutions iPlanet Web Server Enterprise Edition 4.0 SP3 iPlanet E-Commerce Solutions iPlanet Web Server Enterprise Edition 4.0 SP2 iPlanet E-Commerce Solutions iPlanet Web Server Enterprise Edition 4.0 SP1 iPlanet E-Commerce Solutions iPlanet Web Server Enterprise Edition 4.0 |
| Not Vulnerable: |
Sun iPlanet Web Server 4.1 SP7 |
Discussion
iPlanet Web Server Response Header Buffer Overflow Vulnerability
It is possible to trigger an overflow in iPlanet by submitting a malformed 'Host:' header field in an HTTP request. It has been demonstrated that this may cause the server to return sensitive information from memory in the 'Location:' header field of the HTTP response. This may also be used to corrupt memory with attacker-supplied data which may result in execution of malicious code, though this possibility has not been confirmed.
Denial of service may also be possible under some circumstances.
It is possible to trigger an overflow in iPlanet by submitting a malformed 'Host:' header field in an HTTP request. It has been demonstrated that this may cause the server to return sensitive information from memory in the 'Location:' header field of the HTTP response. This may also be used to corrupt memory with attacker-supplied data which may result in execution of malicious code, though this possibility has not been confirmed.
Denial of service may also be possible under some circumstances.
Solution / Fix
iPlanet Web Server Response Header Buffer Overflow Vulnerability
Solution:
This issue has reportedly been addressed in iPlanet versions 4.1SP7 and later. Users are advised to upgrade to the most recent version to address this and other known issues.
Solution:
This issue has reportedly been addressed in iPlanet versions 4.1SP7 and later. Users are advised to upgrade to the most recent version to address this and other known issues.