KPMG-2002021: Resin Large Parameter Denial of Service

From: Peter Gründl (pgrundlat_private)
Date: Mon Jun 17 2002 - 00:23:42 PDT

  • Next message: Kistler Ueli: "ZyXEL 642R(-11) AJ.6 SYN-ACK, SYN-FIN DoS"

    --------------------------------------------------------------------
    
    Title: Resin Large Parameter Denial of Service
    
    BUG-ID: 2002021
    Released: 17th Jun 2002
    --------------------------------------------------------------------
    
    Problem:
    ========
    It is possible for a malicious user to cause a Denial of Service
    by requesting certain malformed URLs from the Resin web server.
    
    
    Vulnerable:
    ===========
    - Resin 2.1.1 standalone on Windows 2000 Server
    
    
    Not Vulnerable:
    ===============
    - Resin 2.1.2 standalone on Windows 2000 Server
    
    
    Details:
    ========
    By defining large variables when accessing non-existant ressources,
    it is possible to consume the entire workspace on the server. This
    will result in hanging parts of or the entire web server.
    
    
    Vendor URL:
    ===========
    You can visit the vendor webpage here: http://www.caucho.com
    
    
    Vendor Response:
    ================
    This was reported to the vendor on the 22nd of May, 2002. On the 11th
    of June, 2002 the vendor released a new version that corrects the
    issue.
    
    
    Corrective action:
    ==================
    Upgrade to version 2.1.2 available from:
    http://www.caucho.com/download/
    
    
    Author: Peter Gründl (pgrundlat_private)
    
    --------------------------------------------------------------------
    KPMG is not responsible for the misuse of the information we provide
    through our security advisories. These advisories are a service to
    the professional security community. In no event shall KPMG be lia-
    ble for any consequences whatsoever arising out of or in connection
    with the use or spread of this information.
    --------------------------------------------------------------------
    



    This archive was generated by hypermail 2b30 : Mon Jun 17 2002 - 08:20:37 PDT