Sun Java System Directory Server 6.x < 6.3.1 LDAP JDBC Backend DoS

This script is Copyright (C) 2009-2013 Tenable Network Security, Inc.


Synopsis :

The remote LDAP server is affected by a denial of service vulnerability.

Description :

The remote host is running the Sun Java System Directory Server, an
LDAP server from Sun Microsystems.

The installed version is older than 6.3.1, and the proxy server
included with such versions is reportedly affected by a denial of
service vulnerability. By sending a specially crafted request to the
JDBC backend through the proxy server, an unauthenticated, remote
attacker may be able to trigger a denial of service condition.

See also :

http://download.oracle.com/sunalerts/1020026.1.html

Solution :

Upgrade to Sun Java System Directory Server version 6.3.1.

Risk factor :

Medium / CVSS Base Score : 5.0
(CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P)
CVSS Temporal Score : 3.7
(CVSS2#E:U/RL:OF/RC:C)
Public Exploit Available : false

Family: Denial of Service

Nessus Plugin ID: 35688 ()

Bugtraq ID: 33761

CVE ID: CVE-2009-0609