Description
Buffer overflow in the ISAPI DLL filter for Macromedia JRun 3.1 allows remote attackers to execute arbitrary code via a direct request to the filter with a long HTTP host header field in a URL for a .jsp file.
Affected products
- macromedia / jrun3.0 – 3.0
- macromedia / jrun3.1 – 3.1
References
- MISChttp://www.securityfocus.com/bid/4873
- MISChttp://online.securityfocus.com/archive/1/274528
- MISChttp://online.securityfocus.com/archive/1/274601
- MISChttp://www.osvdb.org/5082
- VENDOR_ADVISORYhttp://www.cert.org/advisories/CA-2002-14.html
- MISChttp://www.iss.net/security_center/static/9194.php
- MISChttp://archives.neohapsis.com/archives/vulnwatch/2002-q2/0085.html
- MISChttp://www.kb.cert.org/vuls/id/703835