Search:     Advanced search
server monitoring

Oracle WebLogic Server mod_wl Invalid Parameter Remote Overflow (1150354)

Article ID: 34781
Last updated: 27 Jan, 2009
Views: 918
Posted: 22 Jan, 2009
by: Tech Pubs S.
Updated: 27 Jan, 2009
by: Tech Pubs S.

Oracle WebLogic Server mod_wl Invalid Parameter Remote Overflow (1150354)

This script is Copyright (C) 2008-2009 Tenable Network Security, Inc.

FamilyGain root remotely
Plugin ID34781
Bugtraq ID31683
31761
CVE IDCVE-2008-4008

Description:
Synopsis :

The remote web server uses a module that is affected by a buffer
overflow vulnerability.

Description :

The remote web server is using the WebLogic plug-in for Apache
(mod_wl), an Apache module included with Oracle (formerly BEA)
WebLogic Server and used to proxy requests from an Apache HTTP server
to WebLogic.

The version of this plug-in on the remote host is affected by a stack
buffer overflow that is triggered when processing a request with an
invalid parameter. An unauthenticated remote attacker can leverage
this issue to execute arbitrary code on the remote host.

Note that has not tried to exploit this issue but rather has
only checked the affected modules build timestamp.

See also :

http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=751
http://www.securityfocus.com/archive/1/497969/30/0/threaded
http://www.nessus.org/u?e1bbe3e7
http://www.nessus.org/u?d66cba50

Solution :

Install the latest web server plug-in as described in the vendor
advisory above.

Risk factor :

Critical / CVSS Base Score : 10.0
(CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
This article was:   Helpful | Not Helpful
Prev   Next
Golden FTP Server Pro Multiple Command Remote Overflow DoS     Webserver4everyone too long URL