Secunia Advisory SA26326Sun Java System Web Server "redirect" Vulnerability
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Description
A vulnerability has been reported in Sun Java System Web Server, which can be exploited by malicious people to conduct HTTP header injection attacks, HTTP response splitting attacks, and disclose potentially sensitive information. The vulnerability is caused due to an unspecified error within the "redirect" feature and can be exploited if the "redirect" Server Application Function (SAF) is set to use the "url-prefix" parameter in combination with the "escape" parameter set to "no", or if an "Error" directive uses the "url-prefix" parameter in the "obj.conf" file. Solution Provided and/or discovered by Alternate/detailed remediation Deep Links Do you have additional information related to this advisory?Please provide information about patches, mitigating factors, new versions, exploits, faulty patches, links, and other relevant data by posting comments to this Advisory. You can also send this information to vuln@secunia.com
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
221 views | ![]() |
| Debian update for linux-2.6 | |
182 views | ![]() |
| Debian update for moin | |
257 views | ![]() |
| Ubuntu update for MoinMoin | |