Security vulnerability in Sun's IPlanet

Comp. World | at | by Mike

A security vulnerability in the search feature of Sun Microsystems Inc.'s iPlanet Web server can allow attackers to execute code of their choice on remote iPlanet servers, according to a security advisory released today by Next Generation Security Software Ltd. The flaw affects iPlanet Web server Versions 4.1 and 6.0, Next Generation said. Sun has released patches to address the vulnerability in both versions of the software.

IPlanet's search feature is turned off by default; but if it is enabled, a buffer overflow in the "NS-rel-doc-name" parameter can be exploited to give an attacker control over the execution of a vulnerable process, said U.K.-based Next Generation. Gaining such control would give an attacker the ability to run any code with the same access rights as the administrator account running on the Web server, which in some cases would give the attacker unfettered access, the company said.