Note: This is an archival copy of Security Sun Alert 251086 as previously published on http://sunsolve.sun.com.|
Latest version of this security advisory is available from http://support.oracle.com as Sun Alert 1020026.1.
Sun Java System Directory Server Enterprise Edition 6.0
Sun Java System Directory Server Enterprise Edition 6.1
Sun Java System Directory Server Enterprise Edition 6.2
Sun Java System Directory Server Enterprise Edition 6.3
Date of Resolved Release
A Security Vulnerability in the Sun Java System Server, Related to the Directory Proxy Server, May Lead to a Denial of Service (DoS) Condition
A Security Vulnerability in Sun Java System Directory Proxy Server (a component of Sun Java System Directory Server Enterprise Edition) may allow a local or remote unprivileged user to make the Directory Proxy Server unresponsive to certain requests implying a JDBC backend. This is a type of Denial of Service (DoS).
2. Contributing Factors
This issue can occur in the following releases for all platforms (Solaris 9 and 10 on SPARC and x86 Platforms, Linux, Windows, HP-UX and AIX):
PatchZIP (Compressed Archive) and Native package versions:
1. Solaris 8 is not affected by this issue.
2. Sun Java System Directory Server Enterprise Edition 5.x is not affected by this issue.
To determine the version of Directory Proxy Server running on a system, the following command can be run:
$ dpconf -V
Specifically crafted LDAP requests can put the Directory Proxy Server into a state where any further request implying a JDBC backend will become unresponsive until restart of the Directory Proxy Server.
There is no workaround for this issue. Please see the Resolution section below.
This issue is addressed in the following release for all platforms (Solaris 9 and 10 on SPARC and x86 Platforms, Linux, Windows, HP-UX and AIX) for all affected releases (Sun Java System Directory Server Enterprise Edition 6.0, 6.1, 6.2 and 6.3):
Native Package Versions:
Copyright 2000-2009 Sun Microsystems, Inc., 4150 Network Circle, Santa Clara, CA 95054 U.S.A. All rights reserved.
This solution has no attachment