Vulnerability Name: | CVE-2004-0646 (CCN-17485) | ||||||||
Assigned: | 2004-09-23 | ||||||||
Published: | 2004-09-23 | ||||||||
Updated: | 2017-07-11 | ||||||||
Summary: | Buffer overflow in the WriteToLog function for JRun 3.0 through 4.0 web server connectors, such as (1) mod_jrun and (2) mod_jrun20 for Apache, with verbose logging enabled, allows remote attackers to execute arbitrary code via a long HTTP header Content-Type field or other fields. | ||||||||
CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Denial of Service | ||||||||
References: | Source: MITRE Type: CNA CVE-2004-0646 Source: CCN Type: SA12647 ColdFusion MX Sensitive Information Disclosure and Denial of Service Source: SECUNIA Type: UNKNOWN 12647 Source: CCN Type: iDEFENSE Security Advisory 09.29.04 Macromedia JRun 4 mod_jrun Apache Module Buffer Overflow Vulnerability Source: CCN Type: US-CERT VU#990200 Macromedia JRun Server is vulnerable to buffer overflow Source: CERT-VN Type: US Government Resource VU#990200 Source: CONFIRM Type: Patch http://www.macromedia.com/devnet/security/security_zone/mpsb04-08.html Source: CCN Type: Macromedia Security Bulletin MPSB04-09 Cumulative Security Patch available for ColdFusion MX Source: CONFIRM Type: UNKNOWN http://www.macromedia.com/devnet/security/security_zone/mpsb04-09.html Source: CCN Type: OSVDB ID: 10546 Macromedia JRun4 mod_jrun Apache Module Remote Overflow Source: BUGTRAQ Type: UNKNOWN 20040929 iDEFENSE Security Advisory 09.29.04 - Macromedia JRun 4 mod_jrun Apache Module Buffer Overflow Vulnerability Source: BID Type: Patch, Vendor Advisory 11245 Source: CCN Type: BID-11245 Macromedia JRun Multiple Remote Vulnerabilities Source: XF Type: UNKNOWN coldfusion-jrun-verbose-bo(17485) Source: XF Type: UNKNOWN coldfusion-jrun-verbose-bo(17485) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |