Note: This is an archival copy of Security Sun Alert 200471 as previously published on http://sunsolve.sun.com.|
Latest version of this security advisory is available from http://support.oracle.com as Sun Alert 1000349.1.
Sun ONE Application Server 7, Standard Edition
Sun Java System Web Server 6.0 Service Pack 8
Date of Resolved Release
A local or remote unprivileged user may be able to cause the Sun Java System Web Server or the Sun ONE Application Server to exit unexpectedly due to a security vulnerability in Network Security Services (NSS). The ability to disable a Sun Java System Web Server or a Sun ONE Application Server is a type of Denial of Service (DoS).
Additional information about Network Security Services (NSS) is available at:
This issue can occur in the following releases for all platforms:
Note: This issue only affects systems which have SSLv2 enabled. Follow the steps listed in the Relief/Workaround section below to determine if SSLv2 is enabled on the system.
There are no reliable symptoms that would indicate the described issue has been exploited.
To eliminate the possibility of the described issue from occurring, disable SSLv2 and all associated SSLv2 ciphers as shown below:
For Webserver 6.0:
For Appserver 7.0:
This issue is addressed in the following releases:
Sun Java System Web Server 6.0 Service Pack 10 can be found at: http://www.sun.com/download/products.xml?id=43a84f89
Sun ONE Application Server 7 Update can be found at: http://www.sun.com/download/products.xml?id=438cfb75
This solution has no attachment