Rapid7 Vulnerability & Exploit Database

Sun Patch: Oracle iPlanet Web Server 7.0.12 Solaris: Update Release patch

Back to Search

Sun Patch: Oracle iPlanet Web Server 7.0.12 Solaris: Update Release patch

Severity
7
CVSS
(AV:N/AC:M/Au:N/C:P/I:P/A:P)
Published
11/26/2007
Created
07/25/2018
Added
11/26/2007
Modified
05/27/2016

Description

Stack-based buffer overflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, SeaMonkey before 1.0.8, and certain Sun Java System server products before 20070611, allows remote attackers to execute arbitrary code via invalid "Client Master Key" length values.

Solution(s)

  • sunpatch-solaris-125437

References

  • sunpatch-solaris-125437

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;