|
Sun Java System Directory Server HTTP Admin Interface Unspecified Vulnerability
|
|
Secunia Advisory:
|
SA17092
|
|
|
Release Date:
|
2005-10-07
|
|
Last Update:
|
2008-03-17
|
|
Popularity:
|
8,843 views
|
|
|
Critical:
|
 Moderately critical
|
|
Impact:
|
System access
|
|
Where:
|
From local network
|
|
Solution Status:
|
Vendor Patch
|
|
| Software: | Sun Java System Directory Proxy Server 5.x Sun Java System Directory Server 5.x Sun ONE Directory Server 5.x
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
| | CVE reference: | CVE-2005-3269
|
|
Description: Peter Winter-Smith has reported a vulnerability in Sun ONE/Sun Java System Directory Server, Sun Java System Directory Proxy Server, and Sun ONE Administration Server, which can be exploited by malicious people to compromise a vulnerable system.
The vulnerability is caused due to an unspecified error in the HTTP admin interface. This can be exploited to execute arbitrary code with root privileges on a vulnerable system.
The vulnerability has been reported in the following products.
* Sun Java System Directory Proxy Server 5.2
* Sun Java System Directory Server 5.2
* Sun ONE Directory Server 5.1
* Sun ONE Administration Server 5.2
Solution: Apply patches.
-- Packaged versions of Sun ONE Administration Server 5.2 --
Solaris 8, 9, and 10 on SPARC:
Apply patch 115610-23 or later.
http://sunsolve.sun.com/search/docume...setkey=urn:cds:docid:1-21-115610-23-1
Solaris 9 and 10 on x86:
Apply patch 115611-23 or later.
http://sunsolve.sun.com/search/docume...setkey=urn:cds:docid:1-21-115611-23-1
Linux RHEL2.1:
Apply patch 118079-10 or later.
http://sunsolve.sun.com/search/docume...setkey=urn:cds:docid:1-21-118079-10-1
-- Packaged versions of Sun Java System Directory Server 5.2 2003Q4/2004Q2/2005Q1 --
Solaris 8, 9, and 10 on SPARC:
Apply patch 115614-26 or later.
http://sunsolve.sun.com/search/docume...setkey=urn:cds:docid:1-21-115614-26-1
Solaris 8, 9, and 10 on x86:
Apply patch 115615-26 or later.
http://sunsolve.sun.com/search/docume...setkey=urn:cds:docid:1-21-115615-26-1
Linux:
Apply patch 118080-11 or later.
http://sunsolve.sun.com/search/docume...setkey=urn:cds:docid:1-21-118080-11-1
-- Packaged versions of Sun Java System Directory Proxy Server 5.2 2003Q4/2004Q2/2005Q1 --
Solaris 8, 9, and 10 on SPARC:
Apply patch 116373-18 or later.
http://sunsolve.sun.com/search/docume...setkey=urn:cds:docid:1-21-116373-18-1
Solaris 8, 9, and 10 on x86:
Apply patch 116374-14 or later.
http://sunsolve.sun.com/search/docume...setkey=urn:cds:docid:1-21-116374-14-1
Linux:
Apply patch 118096-08 or later.
http://sunsolve.sun.com/search/docume...setkey=urn:cds:docid:1-21-118096-08-1
-- PatchZIP version of Sun Java System Directory Server 5.2 --
For upgrade from 5.2 RTM ZIP or 5.2 Patch2 ZIP or 5.2 Patch3 ZIP.
Solaris 8, 9, and 10 on SPARC:
Apply patch 117665-03 or later.
http://sunsolve.sun.com/search/docume...setkey=urn:cds:docid:1-21-117665-03-1
Solaris 8, 9 and 10 on x86:
Apply patch 117666-03 or later.
http://sunsolve.sun.com/search/docume...setkey=urn:cds:docid:1-21-117666-03-1
Linux:
Apply patch 117668-03 or later.
http://sunsolve.sun.com/search/docume...setkey=urn:cds:docid:1-21-117668-03-1
Windows:
Apply patch 117667-03 or later.
http://sunsolve.sun.com/search/docume...setkey=urn:cds:docid:1-21-117667-03-1
HP-UX:
Apply patch 117669-03 or later.
http://sunsolve.sun.com/search/docume...setkey=urn:cds:docid:1-21-117669-03-1
AIX:
Apply patch 117670-03 or later.
http://sunsolve.sun.com/search/docume...setkey=urn:cds:docid:1-21-117670-03-1
Provided and/or discovered by: Peter Winter-Smith, NGSSoftware
Changelog: 2005-11-23: Vendor releases updated advisory. Updated "Description", "Solution" and "Original Advisory" sections.
2006-01-19: Added CVE reference.
2008-03-17: Updated "Solution" section. According to the vendor there will be no further resolutions to this issue.
Original Advisory: http://sunsolve.sun.com/search/document.do?assetkey=1-26-102002-1
http://sunsolve.sun.com/search/document.do?assetkey=1-66-228419-1
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|
|
|
10th Oct, 2008
|
New advisories:
|
15 |
|
New vulnerabilities:
|
83 |
|
Updated advisories:
|
41 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Solutions | More...
|
|