HTTP: Sun Java System WebDAV Format String

This signature detects attempts to exploit a known vulnerability in Sun Java System Web Server in the WebDAV component. A successful attack can lead to arbitrary remote code execution within the context of the server.

Extended Description

Format string vulnerability in the WebDAV implementation in webservd in Sun Java System Web Server 7.0 Update 6 allows remote attackers to cause a denial of service (daemon crash) and possibly have unspecified other impact via format string specifiers in the encoding attribute of the XML declaration in a PROPFIND request.

Affected Products

Sun java_system_web_server

References

BugTraq: 37910

CVE: CVE-2010-0388

Short Name
HTTP:WEBDAV-FS
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2010-0388 Format Java String Sun System WebDAV bid:37910
Release Date
01/28/2010
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown
Vendors

Sun

CVSS Score

7.5

Found a potential security threat?