Sun Calendar Express Web Server in Sun ONE Calendar Server 6.0 and Sun Java System Calendar Server 6 2004Q2 through 6.3-7.01 allows remote attackers to cause a denial of service (daemon crash) via multiple requests to the default URI with alphabetic characters in the tzid parameter.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://www.vupen.com/english/advisories/2009/0905 | vdb entry |
http://sunsolve.sun.com/search/document.do?assetkey=1-26-256228-1 | patch vendor advisory |
http://www.securityfocus.com/bid/34150 | vdb entry exploit |
http://www.securityfocus.com/archive/1/502320/100/0/threaded | mailing list |
http://sunsolve.sun.com/search/document.do?assetkey=1-66-255008-1 | vendor advisory |
http://www.coresecurity.com/content/sun-calendar-express | exploit |