Likes Likes:  0
Resultaten 1 tot 3 van de 3
Geen
  1. #1
    @stake Advisories
    Windows NT 4.0 with IBM JVM Denial of Service
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Windows NT 4.0 with IBM JVM Denial of Service

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    @stake, Inc.
    www.atstake.com

    Security Advisory


    Advisory Name: Windows NT 4.0 with IBM JVM Denial of Service
    Release Date: 07/23/2003
    Application: Any Java application, other applications
    are possible attack vectors.
    Platform: Java 2 Runtime Environment, Standard Edition
    (build 1.3.0), Windows NT 4.0
    Severity: Denial of service
    Author: Matthew Miller <mmiller@atstake.com>
    Jeremy Rauch
    Vendor Status: Microsoft has patch available
    CVE Candidate: CAN-2003-0525
    Reference: http://www.atstake.com/research/advi.../a072303-1.txt


    Overview:

    A flaw exists in Windows NT 4.0's file name processing. The flaw can
    cause heap corruption to occur when a long string is passed to the
    file name functions. This results in the program calling the NT 4.0
    file name processing functions to crash.

    One attack vector identified by @stake is through a Java servlet
    running on the IBM JVM. This class of problem highlights the Java
    platform's dependance on the correctness of the underlying operating
    system for it's overall security. Java application developers
    should still bounds check untrusted inputs that are passed to the
    underlying operating system API, such as file handling functions.


    Detailed Description:

    A denial of service condition for IBM's Java 2 Runtime Environment
    can be triggered when passing a long string to the
    java.io.getCanonicalPath() function. Any application which passes
    user supplied data to the getCanonicalPath() function is potentially
    vulnerable.

    When passing a long string to java.io.getCanonicalPath() an access
    violation occurs in the Windows NT 4.0 ntdll.dll. This access
    violation causes the IBM JVM to core resulting in a Denial of
    Service. This seems to be due to a corruption of the
    heap.


    Vendor Response:

    Microsoft contacted by @stake: 05/14/2003
    Microsoft reproduced and verified: 06/10/2003

    Microsoft has issued a bulletin and a patch. More information
    is available at:

    http://www.microsoft.com/technet/sec...n/MS03-029.asp


    Recommendation:

    Java developers should identify all occurances and perform data
    validation where java.io.getCanonicalPath is used.

    NT 4.0 Administrators running servers which use Java servlets
    should consider installing the Microsoft supplied patch.


    Common Vulnerabilities and Exposures (CVE) Information:

    The Common Vulnerabilities and Exposures (CVE) project has assigned
    the following names to these issues. These are candidates for
    inclusion in the CVE list (http://cve.mitre.org), which standardizes
    names for security problems.

    CAN-2003-0525


    @stake Vulnerability Reporting Policy:
    http://www.atstake.com/research/policy/

    @stake Advisory Archive:
    http://www.atstake.com/research/advisories/

    PGP Key:
    http://www.atstake.com/research/pgp_key.asc


    Copyright 2003 @stake, Inc. All rights reserved.

    -----BEGIN PGP SIGNATURE-----
    Version: PGP 8.0

    iQA/AwUBPx74oUe9kNIfAm4yEQKc6wCghclEcANjGkrPRGENJyoDhK xyBcYAnjbi
    UiSnzl1p7SRXf+9j7dbRQ/M4
    =10T3
    -----END PGP SIGNATURE-----



  2. #2
    Angelidis, Fotis
    Windows NT 4.0 with IBM JVM Denial of Service
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    RE: Windows NT 4.0 with IBM JVM Denial of Service


    >Microsoft has issued a bulletin and a patch. More information
    >is available at:


    >http://www.microsoft.com/technet/sec...n/MS03-029.asp



    >Recommendation:


    >Java developers should identify all occurances and perform data
    >validation where java.io.getCanonicalPath is used.


    >NT 4.0 Administrators running servers which use Java servlets
    >should consider installing the Microsoft supplied patch.


    After installing the patch on an NT 4 SP 6a server, we experienced problems
    with the RAS manager. Specifically, while the machine was rebooting after
    the update, the familiar "One or more services ..." window popped up.
    Seconds before we pull up the Event Viewer to examine what went wrong during
    the startup Dr. Watson appeared stating that an exception had happened while
    loading loadqm.exe. The Event viewer, on the other hand, showed us three
    main error messages:
    Event ID 7001 - Remote Access Autodial Manager,
    Event ID 7023 - Remote Access Connection Manager and
    Event ID 20067 - Point to Point Protocol failed to initialize.

    Uninstalling the patch didn't help, neither uninstalling/installing the RAS
    service. The only solution which seemed appropriate at the moment was to
    re-install the operating system, which we did.

    After installing and setting up the server, we visited windowsupdate.com.
    Since previously the specific patch was installed following the above link,
    we decided to let Windows Update find the available patches for our case
    this time. The patch was included in the recommended updates, so we
    downloaded all the updates, installed and rebooted the machine.
    Unfortunately, the same errors appeared again. The difference this time was
    that after unistalling the specific patch everything was back to normal,
    fortunately

    Has anybody else experienced any kind of strange behaviour after installing
    this patch ?

  3. #3
    Marc Schoenefeld
    Windows NT 4.0 with IBM JVM Denial of Service
    Gast
    n/a Berichten
    Berichten zijn liked



    Thread Starter

    Re: Windows NT 4.0 with IBM JVM Denial of Service

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    On Wed, 23 Jul 2003, @stake Advisories wrote:

    [..]
    >
    > Advisory Name: Windows NT 4.0 with IBM JVM Denial of Service
    > Release Date: 07/23/2003
    > Application: Any Java application, other applications
    > are possible attack vectors.
    > Platform: Java 2 Runtime Environment, Standard Edition
    > (build 1.3.0), Windows NT 4.0
    > Severity: Denial of service


    Analysis:
    Windows NT 4.0 : outdated
    IBM JAVA 1.3.0 : outdated

    File handling in servlets : Bad design anti-pattern (better use EJB)



    > Recommendation:
    >
    > Java developers should identify all occurances and perform data
    > validation where java.io.getCanonicalPath is used.


    - - That does not help if the getCanonicalPath is used in a
    library that is not available in source code. You might
    have to use a decompiler or use a tool that searches for
    nested calls to such routines. I have written such a tool if
    you like to use it contact me via email.

    - - But generally: Developers should think about system design that does not
    base on direct file access in the web-tier (least function principle).

    >
    > NT 4.0 Administrators running servers which use Java servlets
    > should consider installing the Microsoft supplied patch.


    - - DEPLOYERS should update their JVM (if their code
    does not use proprietary IBM stuff) to an uptodate JVM like
    Sun JRE 1.4.1_03.

    Cheers
    Marc
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.0.6 (AIX)
    Comment: For info see http://www.gnupg.org

    iD8DBQE/IXcHqCaQvrKNUNQRAhbZAJwKjg+jSAOceGRehLaZO1HhET6Uyg CeN1kc
    53vU1gWicAZObo19fSWjxbc=
    =DLEd
    -----END PGP SIGNATURE-----


Webhostingtalk.nl

Contact

  • Rokin 113-115
  • 1012 KP, Amsterdam
  • Nederland
  • Contact
© Copyright 2001-2026 Webhostingtalk.nl.
Web Statistics