[NT] Macromedia ColdFusion/JRun Remote SYSTEM Buffer Overflow Vulnerabilities
From: support@securiteam.comDate: 11/14/02
- Previous message: support@securiteam.com: "[NEWS] Remote Novell Netware Manager Security Issue"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: support@securiteam.com To: list@securiteam.com Date: 14 Nov 2002 15:49:10 +0200
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
Beyond Security would like to welcome Tiscali World Online
to our service provider team.
For more info on their service offering IP-Secure,
please visit http://www.worldonline.co.za/services/work_ip.asp
- - - - - - - - -
Macromedia ColdFusion/JRun Remote SYSTEM Buffer Overflow Vulnerabilities
------------------------------------------------------------------------
SUMMARY
Macromedia JRun and ColdFusion IIS ISAPI handlers contain various heap
overflows when handling URI filenames. By supplying a filename over 4096
bytes in size, heap memory can be overwritten. Various structures can be
overwritten in the process heap to gain control of the remote IIS process
with SYSTEM level access. This makes it rather trivial for attackers to
remotely compromise Microsoft IIS web servers running vulnerable versions
of Macromedia ColdFusion or JRun.
DETAILS
Vulnerable systems:
* Macromedia ColdFusion 6.0 and prior (IIS ISAPI)
* Macromedia JRun 4.0 and prior (IIS ISAPI)
Exploit:
The following requests can be used to duplicate the attack.
For JRun:
telnet example.com 80
GET /[+4096 byte buffer].jsp HTTP/1.0
[enter]
[enter]
For Coldfusion:
telnet example.com 80
GET /[+4096 byte buffer].cfm HTTP/1.0
[enter]
[enter]
During testing, 5000 bytes was sufficient to begin overwriting data
structures that made exploitation straightforward. The vulnerabilities
exist in error handling within the ISAPI filters.
Vendor Status:
Macromedia has released patches for both the JRun and ColdFusion products.
ColdFusion MX Advisory:
<http://www.macromedia.com/v1/handlers/index.cfm?ID=23161>
http://www.macromedia.com/v1/handlers/index.cfm?ID=23161
JRun Advisory:
<http://www.macromedia.com/v1/handlers/index.cfm?ID=23500>
http://www.macromedia.com/v1/handlers/index.cfm?ID=23500
ADDITIONAL INFORMATION
The information has been provided by <mailto:marc@eeye.com> Marc Maiffret
of eEYE.
========================================
This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com
====================
====================
DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
- Previous message: support@securiteam.com: "[NEWS] Remote Novell Netware Manager Security Issue"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
- New Macromedia Security Zone Bulletin Posted
... A new security bulletin describes a configuration problem ... please visit the
Macromedia Security Zone: ... ColdFusion MX 7 cross-site scripting in default error
page ... recommends users patch their installations immediately. ... (Bugtraq) - Macromedia Patch Available for ISAPI buffer overflow in JRun 3.0/ 3.1
... Macromedia has worked with David Litchfield from NGSSoftware regarding his bulletin
... "Macromedia JRUN Buffer overflow vulnerability " ... The text of the bulletin
is below. ... Macromedia has also released a patch that should resolve the issue in JRun
3.1 and 3.0. ... (NT-Bugtraq) - Macromedia Security Bulletin - ColdFusion MX 6.1
... ColdFusion 7.0 is not affected. ... Macromedia has released a workaround
addressing the problem. ... This issue will be fixed in the next updater. ... Reporting
Security Issues: ... (Bugtraq) - FW: Ben Forta Presents at Local User Group
... Ben Forta Presents at Local User Group ... Orange County ColdFusion User
Group on December 9. ... The Orange County CFUG is hosting Macromedia Senior
... (Debian-User) - [NEWS] Duplicate Session IDs Cause JRun Security Vulnerability (Hotfix)
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... * JRun 3.1 ... Macromedia
is currently working on one case that is very specific in its ... Macromedia recommends that users
download the patch corresponding to the ... (Securiteam)