J-Security Center

Title: ColdFusion CFReThrow Tag Denial Of Service Vulnerability

Severity: MODERATE

Description:

ColdFusion is a Web Application software packaged distributed and maintained by Allaire.

A problem with ColdFusion makes it possible for a user to crash a the server, and potentially gain access to sensitive information. The problem is in the handling of the CFRETHROW tag.


CFRETHROW is used to render exception messages when they occur in code on a ColdFusion system. When this tag is used on a ColdFusion system running on Linux, the ColdFusion server crashes, creating a core file in the coldfusion/logs subdirectory of the ColdFusion installation directory.

This core file may contain sensitive information, such as encrypted tags that were being by the ColdFusion server at the time of the crash. This could lead to a local user extracting sensitive information, and compromising further assets.

At the least, this results in denial of service to legitimate users of the ColdFusion system.

Affected Products:

  • Allaire ColdFusion Server 4.5.1
  • Allaire ColdFusion Server 5.0.0

References:

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.