Research Archives > Security Advisories > AD20010515
iPlanet – Netscape Enterprise Web Publisher Buffer Overflow
Release Date:
5/11/2001 12:00:00 AM
Date Reported:
5/11/2001 12:00:00 AM
Severity:
High
Vendor:
iPlanet
Affected Software:
Netscape Enterprise 4.1 and prior versions.
Overview:
The Web Publisher feature in Netscape Enterprise 4.1 is vulnerable to a buffer overflow. By sending a large buffer containing executable code and a new Instruction Pointer, an attacker is able to gain remote system shell access to the vulnerable server.
The overflow itself exists in Publishers handling of the URI (Uniform Resource Identifier). By specifying GETPROPERTIES, GETATTRIBUTENAMES, or any other one of the publisher specific methods, we can pass data into vulnerable section of the server and exploit the vulnerability.
Technical Details:
Example:
C:\>telnet www.example.com 80
Connecting To www.example.com... connected.
GETPROPERTIES /(buffer) HTTP/1.1
Host: Hostname
(enter)
(enter)
Where (buffer) is 2000 characters.
The Exploit:
We have not had time yet to produce a proof of concept exploit, however expect one soon.
Protection:
Vendor Status:
Quote from iPlanet's development team: "The security & stability of iPlanet's customer's environments is one of our paramount concerns. To ensure the stability of our customer's environments iPlanet has made available an NSAPI patch that can be applied to iPlanet web server, Enterprise Edition."
The NSAPI patch is available at:
http://iplanet.com/products/iplanet_web_enterprise/iwsalert5.11.html .
This issue will also be addressed by the release of iPlanet web server, Enterprise Edition version 4.1 Service Pack 8.
Credit:
Riley Hassell
Greetings:
Tool for an amazing new album. NiN for another beautiful single.
Copyright ©1998-2011 eEye Digital Security
Permission is hereby granted for the redistribution of this alert electronically. It is not to be edited in any way without express consent of eEye. If you wish to reprint the whole or any part of this alert in any other medium excluding electronic medium, please email alert@eEye.com for permission.
Disclaimer
The information within this paper may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are no warranties, implied or express, with regard to this information. In no event shall the author be liable for any direct or indirect damages whatsoever arising out of or in connection with the use or spread of this information. Any use of this information is at the user's own risk.