Note: This is an archival copy of Security Sun Alert 228397 as previously published on http://sunsolve.sun.com.
Latest version of this security advisory is available from http://support.oracle.com as Sun Alert 1017342.1.
Article ID : 1017342.1
Article Type : Sun Alerts (SURE)
Last reviewed : 2007-09-03
Audience : PUBLIC
Copyright Notice: Copyright © 2010, Oracle Corporation and/or its affiliates.

Security Vulnerabilities in the Network Security Services (NSS) Library May Affect Sun Java System Application Server, Web Server and Web Proxy Server



Category
Security

Release Phase
Resolved

Product
Sun Java System Application Server Platform Edition 8.1 2005Q1
Sun Java System Web Server 7.0
Sun Java System Web Proxy Server 4.0
Sun Java System Web Server 6.1
Sun Java System Application Server Enterprise Edition 8.1 2005Q1

Bug Id
6546271, 6534224, 6540248

Date of Workaround Release
11-JUN-2007

Date of Resolved Release
04-SEP-2007

Impact

Sun Java System Application Server, Web Server and Proxy Server make use of the Network Security Services (NSS) library and are impacted by a number of security vulnerabilities related to the SSL2 implementation in that library if SSL2 is enabled in these servers. These vulnerabilities may allow remote users to cause the server to exit unexpectedly, causing a denial of service (DoS) to the application, or to execute arbitrary code.

These issues are also described in the following documents:

Other Sun products make use of the NSS library. For information regarding the impact to other products, please see Sun Alert 102856 at:

  • http://sunsolve.sun.com/search/document.do?assetkey=1-26-102856-1

Contributing Factors

These issues can occur in the following releases:

SPARC Platform

  • Sun Java System Application Server Enterprise Edition 8.1 2005 Q1 without (file-based) patch 119169-16 or (SVR4) patch 119166-24
  • Sun Java System Application Server Platform Edition 8.1 2005 Q1 without (file-based) patch 119173-16 or (SVR4) patch 119166-24
  • Sun Java System Web Server 6.1 without Service Pack 8
  • Sun Java System Web Server 6.1 without patch 116648-20
  • Sun Java System Web Server 7.0 without Update 1
  • Sun Java System Web Server 7.0 without patch 125437-07
  • Sun Java System Web Proxy Server 4.0 without Service Pack 5
  • Sun Java System Web Proxy Server 4.0 without patch 120981-12

x86 Platform

  • Sun Java System Application Server Enterprise Edition 8.1 2005 Q1 without (file-based) patch 119170-16 or (SVR4) patch 119167-24
  • Sun Java System Application Server Platform Edition 8.1 2005 Q1 without (file-based) patch 119174-16 or (SVR4) patch 119167-24
  • Sun Java System Web Server 6.1 without Service Pack 8
  • Sun Java System Web Server 6.1 without patch 116649-20
  • Sun Java System Web Server 7.0 without Update 1
  • Sun Java System Web Server 7.0 without patch 125438-07
  • Sun Java System Web Proxy Server 4.0 without Service Pack 5
  • Sun Java System Web Proxy Server 4.0 without patch 120982-12

Linux Platform

  • Sun Java System Application Server Enterprise Edition 8.1 2005 Q1 without (file-based) patch 119171-16 or RHEL2.1/RHEL3.0 (Pkg_patch) 119168-24
  • Sun Java System Application Server Platform Edition 8.1 2005 Q1 without (file-based) patch 119175-16 or RHEL2.1/RHEL3.0 (Pkg_patch) 119168-24
  • Sun Java System Web Server 6.1 without Service Pack 8
  • Sun Java System Web Server 6.1 without patch 118202-12
  • Sun Java System Web Server 7.0 without Update 1
  • Sun Java System Web Server 7.0 without patch 125439-07
  • Sun Java System Web Proxy Server 4.0 without Service Pack 5
  • Sun Java System Web Proxy Server 4.0 without patch 120983-12

AIX Platform

  • Sun Java System Web Server 6.1 without Service Pack 8

HP-UX Platform

  • Sun Java System Web Server 6.1 without Service Pack 8
  • Sun Java System Web Server 6.1 without patch 121510-04
  • Sun Java System Web Server 7.0 without Update 1
  • Sun Java System Web Server 7.0 without patch 125440-01
  • Sun Java System Web Proxy Server 4.0 without Service Pack 5

Windows Platform

  • Sun Java System Application Server Enterprise Edition 8.1 2005 Q1 without (file-based) patch 119172-16 or (package based patch) 122848-09
  • Sun Java System Application Server Platform Edition 8.1 2005 Q1 without (file-based) patch 119176-16
  • Sun Java System Web Server 6.1 without Service Pack 8
  • Sun Java System Web Server 6.1 without patch 121524-04
  • Sun Java System Web Server 7.0 without Update 1
  • Sun Java System Web Server 7.0 without patch 125441-06
  • Sun Java System Web Proxy Server 4.0 without Service Pack 5
  • Sun Java System Web Proxy Server 4.0.5 without patch 126325-02

To determine the version of Sun Java System Application Server on a system, the following command can be run:

    $ <AS_INSTALL>/bin/asadmin version --verbose
    (Where <AS_INSTALL> is the installation directory of the Application Server)

To determine the version of Sun Java System Web Server on a system, the following command can be run:

    $ <WS-install>/https-<host>/start -version
    (Where <WS-install> is the installation directory of the Web Server and <host> should be the actual host name on which the Web Server is installed)

To determine the version of Sun Java System Web Proxy Server on a system, the following command can be run:

    $ <PS_INSTALL>/bin/ns-proxy -v
    (Where <PS_INSTALL> is the installation directory of the Web Proxy Server)

Note: SSL v2 is disabled by default in the Sun Java System Application Server, Sun Java System Web Server, and Sun Java System Web Proxy Server.


Symptoms

There are no reliable symptoms that would indicate the described issues have been exploited.


Workaround

In order to work around these issues in products which use the NSS library, SSL v2 can be disabled. For example if SSL v2 has been enabled in the Sun Java System Application Server, Sun Java System Web Server, or Sun Java System Web Proxy Server then it can be disabled until patches can be applied.

The exact procedure to disable SSL v2 for each of these Sun Java System products varies. See the respective product documentation at http://docs.sun.com for further details.


Resolution

These issues are addressed in the following releases:

SPARC Platform

  • Sun Java System Application Server Enterprise Edition 8.1 2005 Q1 with (file-based) patch 119169-16 or later or (SVR4) patch 119166-24 or later
  • Sun Java System Application Server Platform Edition 8.1 2005 Q1 with (file-based) patch 119173-16 or later or (SVR4) patch 119166-24 or later
  • Sun Java System Web Server 6.1 with Service Pack 8 or later
  • Sun Java System Web Server 6.1 with patch 116648-20 or later
  • Sun Java System Web Server 7.0 with Update 1 or later
  • Sun Java System Web Server 7.0 with patch 125437-07 or later
  • Sun Java System Web Proxy Server 4.0 with Service Pack 5 or later
  • Sun Java System Web Proxy Server 4.0 with patch 120981-12 or later

x86 Platform

  • Sun Java System Application Server Enterprise Edition 8.1 2005 Q1 with (file-based) patch 119170-16 or later or (SVR4) patch 119167-24 or later
  • Sun Java System Application Server Platform Edition 8.1 2005 Q1 with (file-based) patch 119174-16 or later or (SVR4) patch 119167-24 or later
  • Sun Java System Web Server 6.1 with Service Pack 8 or later
  • Sun Java System Web Server 6.1 with patch 116649-20 or later
  • Sun Java System Web Server 7.0 with Update 1 or later
  • Sun Java System Web Server 7.0 with patch 125438-07 or later
  • Sun Java System Web Proxy Server 4.0 with Service Pack 5 or later
  • Sun Java System Web Proxy Server 4.0 with patch 120982-12 or later

Linux Platform

  • Sun Java System Application Server Enterprise Edition 8.1 2005 Q1 with (file-based) patch 119171-16 or later or RHEL2.1/RHEL3.0 (Pkg_patch) 119168-24 or later
  • Sun Java System Application Server Platform Edition 8.1 2005 Q1 with (file-based) patch 119175-16 or later or RHEL2.1/RHEL3.0 (Pkg_patch) 119168-24 or later
  • Sun Java System Web Server 6.1 with Service Pack 8 or later
  • Sun Java System Web Server 6.1 with patch 118202-12 or later
  • Sun Java System Web Server 7.0 with Update 1 or later
  • Sun Java System Web Server 7.0 with patch 125439-07 or later
  • Sun Java System Web Proxy Server 4.0 with Service Pack 5 or later
  • Sun Java System Web Proxy Server 4.0 with patch 120983-12 or later

AIX Platform

  • Sun Java System Web Server 6.1 with Service Pack 8 later

HP-UX Platform

  • Sun Java System Web Server 6.1 with Service Pack 8 or later
  • Sun Java System Web Server 6.1 with patch 121510-04 or later
  • Sun Java System Web Server 7.0 with Update 1 or later
  • Sun Java System Web Server 7.0 with patch 125440-01 or later
  • Sun Java System Web Proxy Server 4.0 with Service Pack 5 or later

Windows Platform

  • Sun Java System Application Server Enterprise Edition 8.1 2005 Q1 with (file-based) patch 119172-16 or later or (package based patch) 122848-09 or later
  • Sun Java System Application Server Platform Edition 8.1 2005 Q1 with (file-based) patch 119176-16 or later
  • Sun Java System Web Server 6.1 with Service Pack 8 or later
  • Sun Java System Web Server 6.1 with patch 121524-04 or later
  • Sun Java System Web Server 7.0 with Update 1 or later
  • Sun Java System Web Server 7.0 with patch 125441-06 or later
  • Sun Java System Web Proxy Server 4.0 with Service Pack 5 or later
  • Sun Java System Web Proxy Server 4.0.5 with patch 126325-02 or later

Sun Java System Web Server 6.1 Service Pack 8 is available at:

Sun Java System Web Server 7.0 Update 1 is available at:

Sun Java System Web Proxy Server 4.0 Service Pack 5 is available at:



Modification History
Date: 29-AUG-2007
  • Updated Contributing Factors and Resolution sections

Date: 04-SEP-2007
  • State: Resolved
  • Updated Contributing Factors and Resolution sections


References

119166-24
119167-24
119168-24
119169-16
119170-16
119171-16
119172-16
122848-09
119173-16
119174-16
119175-16
119176-16
120981-12
120982-12
120983-12
116648-20
116649-20
118202-12
121524-04
125437-07
125438-07
125439-07
125440-01
125441-06
121510-04
126325-02




Attachments
This solution has no attachment