CVE-2000-1049: Medium severity Macromedia JRun vulnerability
Published Dec 11, 2000
·Updated
Allaire JRun 3.0 http servlet server allows remote attackers to cause a denial of service via a URL that contains a long string of "." characters.
Affected Software
2 affected components
Macromedia JRun=3.0-sp1
Macromedia JRun=3.0
Remediation
Event History
Dec 11, 2000
CVE Published
05:00 AM
Jan 22, 2001
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2000-1049?
CVE-2000-1049 is considered to have a high severity rating due to its ability to cause a denial of service.
2
How does CVE-2000-1049 affect Allaire JRun 3.0?
CVE-2000-1049 allows remote attackers to crash the Allaire JRun 3.0 servlet server using specially crafted URLs.
3
How do I fix CVE-2000-1049?
To fix CVE-2000-1049, ensure that Allaire JRun is updated to a version that addresses this vulnerability and implement URL validation.
4
Who is affected by CVE-2000-1049?
CVE-2000-1049 affects users running Allaire JRun version 3.0 and 3.0 service pack 1.
5
What is the nature of the attack for CVE-2000-1049?
The attack for CVE-2000-1049 exploits the handling of URLs with excessive '.' characters to cause a denial of service.