SecurityTracker.com
    Home    |    View Topics    |    Search    |    Contact Us    |   

SecurityTracker
Archives


 


Category:   Application (Web Server/CGI)  >   Sun ONE/iPlanet Web Server Vendors:   Sun
Sun Java System Web Server Lets Remote Users Conduct HTTP Request Smuggling Attacks
SecurityTracker Alert ID:  1017323
SecurityTracker URL:  http://securitytracker.com/id/1017323
CVE Reference:   CVE-2006-6276   (Links to External Site)
Updated:  Feb 27 2007
Original Entry Date:  Dec 1 2006
Impact:   Modification of user information
Fix Available:  Yes  Vendor Confirmed:  Yes  
Version(s): 6.0 SP10, 6.1
Description:   A vulnerability was reported in Sun Java System Web Server. A remote user may be able to conduct HTTP request smuggling attacks.

If the Sun Java System Web Server is used in conjunction with the Sun Java Application Server or Sun Java Proxy Server and if there is an input validation vulnerability in the web server or one of its applications, then a remote user can use HTTP request smuggling techniques to hijack a target user's request or conduct a variation of a cross-site scripting attack against a target user.

A remote user can send multiple HTTP requests with specially crafted HTTP headers to the target server via the proxy/gateway server. The requests may be interpreted differently by the target server than by the proxy/gateway server. As a result, unexpected results may occur. A remote user may be able to poison an intermediate cache, bypass application-level security features within an intermediate proxy/gateway server, or conduct cross-site scripting attacks against target users.

Impact:   A remote user may be able to poison an intermediate cache, bypass application-level security features within an intermediate proxy/gateway server, or conduct cross-site scripting attacks against target users.
Solution:   Sun has issued the following fixes.

SPARC Platform

* Sun Java System Web Server 6.0 without Service Pack 10
* Sun Java System Web Server 6.1 2005Q1 without Service Pack 5

AIX Platform

* Sun Java System Web Server 6.0 with Service Pack 10 or later
* Sun Java System Web Server 6.1 2005Q1 with Service Pack 5 or later

HP-UX Platform

* Sun Java System Web Server 6.0 with Service Pack 10 or later
* Sun Java System Web Server 6.1 2005Q1 with Service Pack 5 or later

The Sun advisory is available at:

http://sunsolve.sun.com/search/document.do?assetkey=1-26-102733-1

Vendor URL:  sunsolve.sun.com/search/document.do?assetkey=1-26-102733-1 (Links to External Site)
Cause:   State error
Underlying OS:  UNIX (AIX), UNIX (HP/UX), UNIX (Solaris - SunOS)

Message History:   None.


 Source Message Contents



[Original Message Not Available for Viewing]


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us

This web site uses cookies for web analytics. Learn More

Copyright 2019, SecurityGlobal.net LLC