Overview
The NSS libraries used in the Sun One Application Server and the Sun Java System web server contain an unspecified vulnerability that may allow an attacker to create a denial-of-service condition.
Description
The Sun One Application Server provides a Java 2 Platform for delivering Java applications and Web services. The Sun Java System web server is a web server that can run on multiple operating systems. Network Security Services (NSS) are a set of libraries that support the development of security enabled applications. An unspecified vulnerability exists in NSS libraries used by the Sun Java System Web Server and the Sun ONE Application Server. |
Impact
A remote, unauthenticated attacker may be able to create a denial of service condition. |
Solution
Upgrade Sun has released updates to address this issue. See Sun Java System Web Server 6.0 Service Pack 10 or Sun ONE Application Server 7 Update for more details. |
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
- http://www.sun.com/software/products/appsrvr/index.xml
- http://www.sun.com/download/products.xml?id=438cfb75
- http://www.sun.com/download/products.xml?id=43a84f89
- http://www.mozilla.org/projects/security/pki/nss/
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-102670-1
- http://en.wikipedia.org/wiki/Ssl
- http://www.frsirt.com/english/advisories/2006/4299
- http://securitytracker.com/id?1017143
- http://secunia.com/advisories/22646
Acknowledgements
Thanks to Sun for information that was used in this report.
This document was written by Ryan Giobbi.
Other Information
CVE IDs: | CVE-2006-5654 |
Severity Metric: | 0.63 |
Date Public: | 2006-11-01 |
Date First Published: | 2007-02-08 |
Date Last Updated: | 2007-02-09 16:04 UTC |
Document Revision: | 34 |