First published: Tue Dec 31 2002(Updated: )
Resin 2.1.1 allows remote attackers to cause a denial of service (thread and connection consumption) via multiple URL requests containing the DOS 'CON' device name and a registered file extension such as .jsp or .xtp.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Caucho Resin | =2.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1989 is considered to have a high severity due to its potential to cause denial of service through resource exhaustion.
To fix CVE-2002-1989, upgrade to a newer version of Resin that does not contain the vulnerability.
CVE-2002-1989 affects Resin version 2.1.1, specifically.
Yes, CVE-2002-1989 can be exploited remotely by sending multiple crafted URL requests.
CVE-2002-1989 involves a denial of service attack that leads to thread and connection consumption.