---------------------------------------------------------------------- Do you need accurate and reliable IDS / IPS / AV detection rules? Get in-depth vulnerability details: http://secunia.com/binary_analysis/sample_analysis/ ---------------------------------------------------------------------- TITLE: Sun Java System LDAP JDK Information Disclosure Vulnerability SECUNIA ADVISORY ID: SA32327 VERIFY ADVISORY: http://secunia.com/advisories/32327/ CRITICAL: Less critical IMPACT: Exposure of sensitive information WHERE: Local system SOFTWARE: Sun Java System Access Manager 7.x http://secunia.com/advisories/product/7284/ Sun Java System Access Manager 6.x http://secunia.com/advisories/product/13379/ Sun Java System LDAP Java Development Kit 4.x http://secunia.com/advisories/product/20240/ DESCRIPTION: A vulnerability has been reported in Sun Java System LDAP JDK, which can be exploited by malicious, local users to disclose potentially sensitive information. The vulnerability is caused due to an unspecified error in the search feature of the Sun Java System LDAP JDK and can be exploited to disclose information from applications that use the LDAP JDK library. The vulnerability is reported in Sun Java System LDAP JDK prior to version 4.20, as included in Sun Java System Access Manager. SOLUTION: Apply patches (see vendor advisory for further information). -- SPARC Platform -- Sun Java System LDAP JDK 4.19 or earlier for Sun Java System Access Manager 6 2005Q1 (for Solaris 8, 9 and 10): Apply patch 119725-05 http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21-119725-05-1 Sun Java System LDAP JDK 4.19 or earlier for Sun Java System Access Manager 7 2005Q4 (for Solaris 8, 9 and 10): Apply patch 119725-05 http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21-119725-05-1 Sun Java System LDAP JDK 4.19 or earlier for Sun Java System Access Manager 7.1 (for Solaris 8, 9 and 10): Apply patch 119725-05. http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21-119725-05-1 -- x86 Platform -- Sun Java System LDAP JDK 4.19 or earlier for Sun Java System Access Manager 6 2005Q1 (for Solaris 8, 9 and 10): Apply patch 119725-05. http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21-119725-05-1 Sun Java System LDAP JDK 4.19 or earlier Sun Java System Access Manager 7 2005Q4, (for Solaris 8, 9 and 10): Apply patch 119725-05. http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21-119725-05-1 Sun Java System LDAP JDK 4.19 or earlier for Sun Java System Access Manager 7.1 (for Solaris 9 and 10): Apply patch 119725-05. http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21-119725-05-1 -- Linux Platform -- Sun Java System LDAP JDK 4.19 or earlier for Sun Java System Access Manager 6 2005Q1 (for RHEL2.1): Apply patch 120834-03. http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21-120834-03-1 Sun Java System LDAP JDK 4.19 or earlier for Sun Java System Access Manager 7 2005Q4 (for RHEL2.1): Apply patch 120834-03. http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21-120834-03-1 Sun Java System LDAP JDK 4.19 or earlier for Sun Java System Access Manager 7.1 (for RHEL2.1): Apply patch 120834-03. http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21-120834-03-1 -- HP-UX Platform -- Sun Java System LDAP JDK 4.19 or earlier: Apply patch 138905-01. http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21-138905-01-1 -- Windows Platform -- Sun Java System LDAP JDK 4.19 or earlier: Apply patch 138905-01. http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21-138905-01-1 PROVIDED AND/OR DISCOVERED BY: Reported by the vendor. ORIGINAL ADVISORY: http://sunsolve.sun.com/search/document.do?assetkey=1-66-242246-1 ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help everybody keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/advisories/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/advisories/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------