Digital Edition

SYS-CON.TV
NGSSoftware Reports Vulnerability in JRun 3.1, Corrected in 4.0 Version
NGSSoftware Reports Vulnerability in JRun 3.1, Corrected in 4.0 Version

(June 5, 2002) - A buffer overrun vulnerability in Macromedia's JRun 3.1 server, installed on Microsoft's Internet Information Services 4 and 5 on Windows NT 4 and 2000, could allow an attacker to remotely gain complete control of the server, according to an alert posted by Next Generation Security Software.

Previously owned by Allaire, Macromedia JRun is a J2EE server designed to run on Web servers to deliver Java-based online applications. NGSSoftware alerted Macromedia to this problem at the start of April, and since then JRun 4 has been released. This version contains the fix to prevent the overrun. Also, a security patch has been created to address this problem. NGSSoftware advises JRun 3.1 users to upgrade to JRun 4 as soon as possible. For more details, see Macromedia's site, www.macromedia.com/v1/Handlers/index.cfm?ID=22273&Method=Full , or go to www.nextgenss.com/advisories/jrun.txt. At www.nextgenss.com/, vendor notification alerts are also posted for Microsoft SQL Server 2000, Sun iPlanet Web Server 6, and Microsoft HTML Help.

About Java News Desk
JDJ News Desk monitors the world of Java to present IT professionals with updates on technology advances, business trends, new products and standards in the Java and i-technology space.

In order to post a comment you need to be registered and logged in.

Register | Sign-in

Reader Feedback: Page 1 of 1



ADS BY GOOGLE
Subscribe to the World's Most Powerful Newsletters

ADS BY GOOGLE

HyperConvergence came to market with the objective of being simple, flexible and to help drive down ...
The best way to leverage your CloudEXPO | DXWorldEXPO presence as a sponsor and exhibitor is to plan...
JETRO showcased Japan Digital Transformation Pavilion at SYS-CON's 21st International Cloud Expo® at...
@DevOpsSummit at Cloud Expo, taking place November 12-13 in New York City, NY, is co-located with 22...
With 10 simultaneous tracks, keynotes, general sessions and targeted breakout classes, @CloudEXPO an...
DXWorldEXPO LLC announced today that the upcoming DXWorldEXPO | CloudEXPO New York event will featur...
22nd International Cloud Expo, taking place June 5-7, 2018, at the Javits Center in New York City, N...
"We're focused on how to get some of the attributes that you would expect from an Amazon, Azure, Goo...
In his keynote at 19th Cloud Expo, Sheng Liang, co-founder and CEO of Rancher Labs, discussed the te...
We all know that end users experience the Internet primarily with mobile devices. From an app develo...
We all know that end users experience the internet primarily with mobile devices. From an app develo...
We all know that end users experience the internet primarily with mobile devices. From an app develo...
All organizations that did not originate this moment have a pre-existing culture as well as legacy t...
DXWorldEXPO LLC announced today that All in Mobile, a mobile app development company from Poland, wi...
We are seeing a major migration of enterprises applications to the cloud. As cloud and business use ...
Founded in 2000, Chetu Inc. is a global provider of customized software development solutions and IT...
DXWorldEXPO LLC announced today that Dez Blanchfield joined the faculty of CloudEXPO's "10-Year Anni...
In his session at 21st Cloud Expo, James Henry, Co-CEO/CTO of Calgary Scientific Inc., introduced yo...
One of the biggest challenges with adopting a DevOps mentality is: new applications are easily adapt...
I think DevOps is now a rambunctious teenager - it's starting to get a mind of its own, wanting to g...