Family: Gain root remotely --> Category: destructive_attack
iPlanet chunked encoding Vulnerability Scan
Vulnerability Scan Summary
Checks for the behavior of iPlanet
Detailed Explanation for this Vulnerability Test
This host is running the Sun One/iPlanet web server 4.1 or 6.0. This
web server contains an unchecked buffer in the 'Chunked Encoding'
processing routines. By issuing a malformed request to the web server,
a potential intruder can 'POST' extraneous data and cause the web
server process to execute arbitrary code. This allows the potential
intruder to gain access to this host.
Solution: The vendor has released Sun ONE web server 4.1 service
pack 11 and 6.0 service pack 4 to fix this issue. Please install the
latest service pack available from Sun's website at http://www.sun.com/
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.