[26019] in bugtraq

home help back first fref pref prev next nref lref last post

KPMG-2002026: Jrun sourcecode Disclosure

daemon@ATHENA.MIT.EDU (=?iso-8859-1?Q?Peter_Gr=FCndl?=)
Mon Jul 1 16:19:20 2002

Message-ID: <005201c220cf$77ee4be0$4700a8c0@kpmguek0e8d7an>
From: =?iso-8859-1?Q?Peter_Gr=FCndl?= <pgrundl@kpmg.dk>
To: "bugtraq" <bugtraq@securityfocus.com>
Date: Mon, 1 Jul 2002 09:18:16 +0200
MIME-Version: 1.0
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Transfer-Encoding: 8bit

--------------------------------------------------------------------

Title: Jrun sourcecode Disclosure

BUG-ID: 2002026
Released: 01st Jul 2002
--------------------------------------------------------------------

Problem:
========
It is possible for a malicious user to trick the Jrun webserver into
disclosing sourcecode.


Vulnerable:
===========
- Jrun 4.0 on Windows 2000 Server

Other versions were not tested!


Details:
========
There are several strings that can be attacked to a legitimate
request to fool the webserver into serving up the unparsed .jsp file
The problem is with the handling of null characters in the request
string and one way to trigger it is to append a unicoded null to
the valid request string.


Vendor URL:
===========
You can visit the vendor webpage here: http://www.macromedia.com


Vendor Response:
================
This was reported to the vendor on the 17th of May, 2002. On the
27th of June, 2002, the vendor released a cumulative patch for
Jrun that includes the patch for this issue.


Corrective action:
==================
Read the vendors advisory to determine which patch you need:

http://www.macromedia.com/v1/handlers/index.cfm?ID=23164



Author: Peter Gründl (pgrundl@kpmg.dk)

--------------------------------------------------------------------
KPMG is not responsible for the misuse of the information we provide
through our security advisories. These advisories are a service to
the professional security community. In no event shall KPMG be lia-
ble for any consequences whatsoever arising out of or in connection
with the use or spread of this information.
--------------------------------------------------------------------


home help back first fref pref prev next nref lref last post