exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Secunia Security Advisory 37566

Secunia Security Advisory 37566
Posted Dec 3, 2009
Authored by Secunia | Site secunia.com

Secunia Security Advisory - Sun has acknowledged a vulnerability in Sun Solaris and Sun Java Enterprise System, which can be exploited by malicious people to manipulate certain data.

tags | advisory, java
systems | solaris
SHA-256 | 9eb16fb207fb36596949feadcba4f38a36d92df9590050a9822ee98f8eced587

Secunia Security Advisory 37566

Change Mirror Download
----------------------------------------------------------------------

Do you have VARM strategy implemented?

(Vulnerability Assessment Remediation Management)

If not, then implement it through the most reliable vulnerability
intelligence source on the market.

Implement it through Secunia.

For more information visit:
http://secunia.com/advisories/business_solutions/

Alternatively request a call from a Secunia representative today to
discuss how we can help you with our capabilities contact us at:
sales@secunia.com

----------------------------------------------------------------------

TITLE:
Sun Products NSS TLS Session Renegotiation Plaintext Injection
Vulnerability

SECUNIA ADVISORY ID:
SA37566

VERIFY ADVISORY:
http://secunia.com/advisories/37566/

DESCRIPTION:
Sun has acknowledged a vulnerability in Sun Solaris and Sun Java
Enterprise System, which can be exploited by malicious people to
manipulate certain data.

For more information:
SA37291

SOLUTION:
The vulnerability is fixed in the following applications, which do
not rely on TLS session renegotiation:

-- Linux --

Sun Java Enterprise System 2005Q4 and Sun Java Enterprise System 5
(for RHEL2.1 and RHEL3.0):
Apply patch 142506-03 or later

Sun Java Enterprise System 5 (for RHEL4.0 and RHEL5.0):
Apply patch 121656-21 or later


-- HP-UX --

Sun Java Enterprise System 2005Q4 and Sun Java Enterprise System 5:
Apply patch 124379-12 or later


-- Windows --

Sun Java Enterprise System 2005Q4:
Apply patch 124392-11 or later

Sun Java Enterprise System 5:
Apply patch 125923-10 or later


Preliminary Temporary Patches have been released for the following
applications, which disables TLS session renegotiation:
http://sunsolve.sun.com/tpatches

-- SPARC Platform --

Solaris 8:
T-Patch T119209-22

Solaris 9:
T-Patch T119211-22

Solaris 10:
T-Patch T119213-21

Sun Java Enterprise System 5 (for Solaris 8, Solaris 9, and Solaris
10):
T-Patch T125358-10


-- X86 Platform --

Solaris 9:
T-Patch T119212-22

Solaris 10:
T-Patch T119214-21

Sun Java Enterprise System 5 (for Solaris 8, Solaris 9, and Solaris
10):
T-Patch T125359-10

ORIGINAL ADVISORY:
http://sunsolve.sun.com/search/document.do?assetkey=1-66-273350-1

OTHER REFERENCES:
SA37291:
http://secunia.com/SA37291/

----------------------------------------------------------------------

About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.

Subscribe:
http://secunia.com/advisories/secunia_security_advisories/

Definitions: (Criticality, Where etc.)
http://secunia.com/advisories/about_secunia_advisories/


Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.

----------------------------------------------------------------------

Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    63 Files
  • 14
    Nov 14th
    18 Files
  • 15
    Nov 15th
    8 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    17 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close