Coldfusion 8.01, Nessus Finding CVE-2002-0894


hello;

i have problem security issue cve-2002-0894 , cve-2000-0681.

we use cf 8.01 enterprise under windows server 2003 iis 6.0 webserver.

 

our internal scans find issue servletexec 4.1 / jrun isapi multiple dos.

description: sending overly long request .jsp file, possible crash remote web server. 



this problem known servletexec / jrun isapi dos.

download patch #9 ftp://ftp.newatlanta.com/public/4_1/patches/

see also
http://www.westpoint.ltd.uk/advisories/wp-02-0006.txt

no more infos.

------------------------------------------------------------------------------------------ -------

 

but can't find on adobe websites or in in cve database direct link coldfusion or adobe patches (apsb xxx).

no info, how fix finding or install patch under cold fusion.

 

has experiences topic cve-2002-0894 , cve-2000-0681 under coldfusion or give me advisory.

 

thank's frank



More discussions in ColdFusion


adobe

Comments

Popular posts from this blog

how to devide a circle into equal parts

"Could not fill because there are not enough opaque source pixels" - not solved by any other thread

Why can't I change the billing info for my account?