mailing list archives
iPlanet - Netscape Enterprise Web Publisher Buffer Overflo w
From: "Marc Maiffret" <marc () eeye com>
Date: Tue, 15 May 2001 16:08:54 -0700
iPlanet Netscape Enterprise Web Publisher Buffer Overflow
May 11, 2001
High (Remote SYSTEM level code execution)
Netscape Enterprise 4.1 and prior versions.
The Web Publisher feature in Netscape Enterprise 4.1 is vulnerable to a
buffer overflow. By sending a large buffer containing executable code and a
new Instruction Pointer, an attacker is able to gain remote system shell
access to the vulnerable server.
The overflow itself exists in Publishers handling of the URI (Uniform
Resource Identifier). By specifying GETPROPERTIES, GETATTRIBUTENAMES, or any
other one of the publisher specific methods, we can pass data into
vulnerable section of the server and exploit the vulnerability.
C:\>telnet www.example.com 80
Connecting To www.example.com... connected.
GETPROPERTIES /(buffer) HTTP/1.1
Where (buffer) is 2000 characters.
We have not had time yet to produce a proof of concept exploit, however
expect one soon.
Quote from iPlanet's development team: "The security & stability of
iPlanet's customer's environments is one of our paramount concerns. To
ensure the stability of our customer's environments iPlanet has made
available an NSAPI patch that can be applied to iPlanet Web Server,
The NSAPI patch is available at:
This issue will also be addressed by the release of iPlanet Web Server,
Enterprise Edition version 4.1 Service Pack 8.
Riley Hassell (riley () eeye com)
SecureIIS, Stop known and unknown IIS web server vulnerabilities.
Retina, The Network Security Scanner. http://www.eeye.com/Retina
Tool for an amazing new album. NiN for another beautiful single.
Copyright (c) 1998-2001 eEye Digital Security
Permission is hereby granted for the redistribution of this alert
electronically. It is not to be edited in any way without express consent of
eEye. If you wish to reprint the whole or any part of this alert in any
other medium excluding electronic medium, please e-mail alert () eEye com for
The information within this paper may change without notice. Use of this
information constitutes acceptance for use in an AS IS condition. There are
NO warranties with regard to this information. In no event shall the author
be liable for any damages whatsoever arising out of or in connection with
the use or spread of this information. Any use of this information is at the
user's own risk.
Please send suggestions, updates, and comments to:
eEye Digital Security
info () eEye com
- iPlanet - Netscape Enterprise Web Publisher Buffer Overflo w Marc Maiffret (May 16)