iPlanet Web Server Response Header Buffer Overflow Vulnerability

BID:6826

Info

iPlanet Web Server Response Header Buffer Overflow Vulnerability

Bugtraq ID: 6826
Class: Boundary Condition Error
CVE:
Remote: Yes
Local: No
Published: Apr 16 2001 12:00AM
Updated: Apr 16 2001 12:00AM
Credit: Discovery of this issue is credited to @stake.
Vulnerable: Sun iPlanet Web Server 4.1 SP6
Sun iPlanet Web Server 4.1 SP5
Sun iPlanet Web Server 4.1 SP4
Sun iPlanet Web Server 4.1 SP3
Sun iPlanet Web Server 4.1 SP2
Sun iPlanet Web Server 4.1 SP1
Sun iPlanet Web Server 4.1
- HP HP-UX 11.0
- IBM AIX 4.3.3
- Linux kernel 2.2.12
- Microsoft Windows NT 4.0
iPlanet E-Commerce Solutions iPlanet Web Server Enterprise Edition 4.0 SP6
iPlanet E-Commerce Solutions iPlanet Web Server Enterprise Edition 4.0 SP5
iPlanet E-Commerce Solutions iPlanet Web Server Enterprise Edition 4.0 SP4
iPlanet E-Commerce Solutions iPlanet Web Server Enterprise Edition 4.0 SP3
iPlanet E-Commerce Solutions iPlanet Web Server Enterprise Edition 4.0 SP2
iPlanet E-Commerce Solutions iPlanet Web Server Enterprise Edition 4.0 SP1
iPlanet E-Commerce Solutions iPlanet Web Server Enterprise Edition 4.0
- Compaq Tru64 5.1
- Compaq Tru64 5.0 a
- HP HP-UX 11.0
- HP HP-UX 11i v1
- Microsoft Windows 2000 Professional SP2
- Microsoft Windows 2000 Professional SP1
- Microsoft Windows NT 4.0 SP6a
- Microsoft Windows NT 4.0 SP6
- Redhat Linux 6.2
- Sun Solaris 8_sparc
- Sun Solaris 7.0
- Sun Solaris 2.6
Not Vulnerable: Sun iPlanet Web Server 4.1 SP7

Discussion

iPlanet Web Server Response Header Buffer Overflow Vulnerability

It is possible to trigger an overflow in iPlanet by submitting a malformed 'Host:' header field in an HTTP request. It has been demonstrated that this may cause the server to return sensitive information from memory in the 'Location:' header field of the HTTP response. This may also be used to corrupt memory with attacker-supplied data which may result in execution of malicious code, though this possibility has not been confirmed.

Denial of service may also be possible under some circumstances.

Solution / Fix

iPlanet Web Server Response Header Buffer Overflow Vulnerability

Solution:
This issue has reportedly been addressed in iPlanet versions 4.1SP7 and later. Users are advised to upgrade to the most recent version to address this and other known issues.

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report