(HP Issues Fix for OpenView) Java Secure Socket Extension (JSSE) SSL/TLS Handshake Bug Lets Remote Users Deny Service
|
|
SecurityTracker Alert ID: 1021756 |
|
SecurityTracker URL: http://securitytracker.com/id/1021756
|
|
CVE Reference:
CVE-2007-3698
(Links to External Site)
|
Date: Feb 25 2009
|
Impact:
Denial of service via network
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): 7.01, 7.51, 7.53
|
Description:
A vulnerability was reported in Java Secure Socket Extension (JSSE). A remote user can cause denial of service conditions. HP OpenView Network Node Manager is affected.
JSSE does not properly process SSL/TLS handshake requests. A remote user can send a specially crafted request to cause the target system to crash.
Sun credits Cisco Systems with reporting this vulnerability.
|
Impact:
A remote user can cause the target system to crash.
|
Solution:
HP has issued a fix for HP OpenView Network Node Manager, which is affected by this vulnerability.
The HP advisory is available at:
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01601492
|
Vendor URL: h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01601492 (Links to External Site)
|
Cause:
Exception handling error
|
Underlying OS:
Linux (Any), UNIX (HP/UX), UNIX (Solaris - SunOS), Windows (Any)
|
|
Message History:
This archive entry is a follow-up to the message listed below.
|
Source Message Contents
|
Date: Tue, 24 Feb 2009 19:24:07 -0500
Subject: HPSBMA02384 SSRT071465 rev.1 - HP OpenView Network Node Manager (OV NNM), Remote Unauthorized Access, Denial of Service (DoS)
|
https://www11.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c01601492
CVE-2007-3698, CVE-2007-3922
|
|