Java Secure Socket Extension (JSSE) SSL/TLS Handshake Bug Lets Remote Users Deny Service
|
|
SecurityTracker Alert ID: 1018357
|
|
SecurityTracker URL: http://securitytracker.com/id?1018357
|
|
CVE Reference: CVE-2007-3698
(Links to External Site)
|
Updated: Jul 25 2007
|
Original Entry Date: Jul 10 2007
|
Impact: Denial of service via network
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Advisory: Sun Alert
|
Version(s): JRE 6 Update 1 and prior versions
|
Description: A vulnerability was reported in Java Secure Socket Extension (JSSE). A remote user can cause denial of service conditions.
JSSE does not properly process SSL/TLS handshake requests. A remote user can send a specially crafted request to cause the target system to crash.
Sun credits Cisco Systems with reporting this vulnerability.
|
Impact: A remote user can cause the target system to crash.
|
Solution: Sun has issued the following fixes.
* JDK and JRE 6 Update 2 or later
* JDK and JRE 5.0 Update 12 and later
* SDK
and JRE 1.4.2_15 and later
Java SE 6 is available for download at the following links:
http://java.sun.com/javase/downloads/index.jsp
Java
SE 6 Update 2 for Solaris is available in the following patches:
* Java SE 6: update 2 (as delivered in patch 125136-02 or
later)
* Java SE 6: update 2 (as delivered in patch 125137-02 or later (64bit))
* Java SE 6_x86: update 2 (as delivered
in patch 125138-02 or later)
* Java SE 6_x86: update 2 (as delivered in patch 125139-02 or later (64bit))
Java SE 5.0 is
available for download at the following link:
http://java.sun.com/j2se/1.5.0/download.jsp
Java SE 5.0 Update 12 for Solaris
is available in the following patches:
* J2SE 5.0: update 12 (as delivered in patch 118666-12 or later)
* J2SE 5.0:
update 12 (as delivered in patch 118667-12 or later (64bit))
* J2SE 5.0_x86: update 12 (as delivered in patch 118668-12 or
later)
* J2SE 5.0_x86: update 12 (as delivered in patch 118669-12 or later (64bit))
J2SE 1.4.2 is available for download
at the following link:
http://java.sun.com/j2se/1.4.2/download.html
The Sun advisory is available at:
http://sunsolve.sun.com/search/document.do?assetkey=1-26-10
2997-1
|
Vendor URL: sunsolve.sun.com/search/document.do?assetkey=1-26-102997-1 (Links to External Site)
|
Cause: Exception handling error
|
Underlying OS: Linux (Any), UNIX (Solaris - SunOS), Windows (Any)
|
|
Message History:
This archive entry has one or more follow-up message(s) listed below.
|
Source Message Contents
|
Date: Tue, 10 Jul 2007 15:34:10 -0400
Subject: Java Secure Socket Extension Does Not Correctly Process SSL/TLS Handshake Requests Resulting in a Denial of Service (DoS) Condition
|
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102997-1
|
|