CVE-2005-3269

Stack-based buffer overflow in help.cgi in the HTTP administrative interface for (1) Sun Java System Directory Server 5.2 2003Q4, 2004Q2, and 2005Q1, (2) Red Hat Directory Server and (3) Certificate Server before 7.1 SP1, (4) Sun ONE Directory Server 5.1 SP4 and earlier, and (5) Sun ONE Administration Server 5.2 allows remote attackers to cause a denial of service (admin server crash), or local users to gain root privileges.
References
Link Resource
http://marc.info/?l=bugtraq&m=112862037500012&w=2
http://marc.info/?l=bugtraq&m=113815459026080&w=2
http://secunia.com/advisories/17092 Vendor Advisory
http://secunia.com/advisories/18590 Vendor Advisory
http://securityreason.com/securityalert/367
http://securityreason.com/securityalert/51
http://securitytracker.com/id?1015014
http://securitytracker.com/id?1015536
http://securitytracker.com/id?1015537
http://securitytracker.com/id?1015538
http://sunsolve.sun.com/search/document.do?assetkey=1-21-117665-03-1 Patch
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102002-1
http://sunsolve.sun.com/search/document.do?assetkey=1-66-228419-1
http://www.securityfocus.com/bid/15013
http://www.securityfocus.com/bid/16345
http://www.vupen.com/english/advisories/2005/1988 Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/24311
http://marc.info/?l=bugtraq&m=112862037500012&w=2
http://marc.info/?l=bugtraq&m=113815459026080&w=2
http://secunia.com/advisories/17092 Vendor Advisory
http://secunia.com/advisories/18590 Vendor Advisory
http://securityreason.com/securityalert/367
http://securityreason.com/securityalert/51
http://securitytracker.com/id?1015014
http://securitytracker.com/id?1015536
http://securitytracker.com/id?1015537
http://securitytracker.com/id?1015538
http://sunsolve.sun.com/search/document.do?assetkey=1-21-117665-03-1 Patch
http://sunsolve.sun.com/search/document.do?assetkey=1-26-102002-1
http://sunsolve.sun.com/search/document.do?assetkey=1-66-228419-1
http://www.securityfocus.com/bid/15013
http://www.securityfocus.com/bid/16345
http://www.vupen.com/english/advisories/2005/1988 Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/24311
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sun:java_system_directory_proxy_server:5.2:2003q4:*:*:*:*:*:*
cpe:2.3:a:sun:java_system_directory_proxy_server:5.2:2004q2:*:*:*:*:*:*
cpe:2.3:a:sun:java_system_directory_proxy_server:5.2:2005q1:*:*:*:*:*:*
cpe:2.3:a:sun:java_system_directory_server:5.2:*:*:*:*:*:*:*
cpe:2.3:a:sun:java_system_directory_server:5.2:2003q4:*:*:*:*:*:*
cpe:2.3:a:sun:java_system_directory_server:5.2:2004q2:*:*:*:*:*:*
cpe:2.3:a:sun:java_system_directory_server:5.2:2005q1:*:*:*:*:*:*
cpe:2.3:a:sun:one_administration_server:5.2:*:*:*:*:*:*:*
cpe:2.3:a:sun:one_directory_server:4.16:*:*:*:*:*:*:*
cpe:2.3:a:sun:one_directory_server:4.16:sp1:*:*:*:*:*:*
cpe:2.3:a:sun:one_directory_server:5.0:*:*:*:*:*:*:*
cpe:2.3:a:sun:one_directory_server:5.0:sp1:*:*:*:*:*:*
cpe:2.3:a:sun:one_directory_server:5.0_sp2:*:*:*:*:*:*:*
cpe:2.3:a:sun:one_directory_server:5.1:*:*:*:*:*:*:*
cpe:2.3:a:sun:one_directory_server:5.1:*:x86:*:*:*:*:*
cpe:2.3:a:sun:one_directory_server:5.1:sp1:*:*:*:*:*:*
cpe:2.3:a:sun:one_directory_server:5.1:sp2:*:*:*:*:*:*
cpe:2.3:a:sun:one_directory_server:5.1:sp3:*:*:*:*:*:*
cpe:2.3:a:sun:one_directory_server:5.1:sp3:x86:*:*:*:*:*
cpe:2.3:a:sun:one_directory_server:5.1:sp4:*:*:*:*:*:*

History

21 Nov 2024, 00:01

Type Values Removed Values Added
References () http://marc.info/?l=bugtraq&m=112862037500012&w=2 - () http://marc.info/?l=bugtraq&m=112862037500012&w=2 -
References () http://marc.info/?l=bugtraq&m=113815459026080&w=2 - () http://marc.info/?l=bugtraq&m=113815459026080&w=2 -
References () http://secunia.com/advisories/17092 - Vendor Advisory () http://secunia.com/advisories/17092 - Vendor Advisory
References () http://secunia.com/advisories/18590 - Vendor Advisory () http://secunia.com/advisories/18590 - Vendor Advisory
References () http://securityreason.com/securityalert/367 - () http://securityreason.com/securityalert/367 -
References () http://securityreason.com/securityalert/51 - () http://securityreason.com/securityalert/51 -
References () http://securitytracker.com/id?1015014 - () http://securitytracker.com/id?1015014 -
References () http://securitytracker.com/id?1015536 - () http://securitytracker.com/id?1015536 -
References () http://securitytracker.com/id?1015537 - () http://securitytracker.com/id?1015537 -
References () http://securitytracker.com/id?1015538 - () http://securitytracker.com/id?1015538 -
References () http://sunsolve.sun.com/search/document.do?assetkey=1-21-117665-03-1 - Patch () http://sunsolve.sun.com/search/document.do?assetkey=1-21-117665-03-1 - Patch
References () http://sunsolve.sun.com/search/document.do?assetkey=1-26-102002-1 - () http://sunsolve.sun.com/search/document.do?assetkey=1-26-102002-1 -
References () http://sunsolve.sun.com/search/document.do?assetkey=1-66-228419-1 - () http://sunsolve.sun.com/search/document.do?assetkey=1-66-228419-1 -
References () http://www.securityfocus.com/bid/15013 - () http://www.securityfocus.com/bid/15013 -
References () http://www.securityfocus.com/bid/16345 - () http://www.securityfocus.com/bid/16345 -
References () http://www.vupen.com/english/advisories/2005/1988 - Vendor Advisory () http://www.vupen.com/english/advisories/2005/1988 - Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/24311 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/24311 -

Information

Published : 2005-10-20 23:02

Updated : 2024-11-21 00:01


NVD link : CVE-2005-3269

Mitre link : CVE-2005-3269

CVE.ORG link : CVE-2005-3269


JSON object : View

Products Affected

sun

  • one_directory_server
  • java_system_directory_server
  • one_administration_server
  • java_system_directory_proxy_server
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer