First published: Mon Dec 28 2009(Updated: )
Directory Proxy Server (DPS) in Sun Java System Directory Server Enterprise Edition 6.0 through 6.3.1 does not properly implement the max-client-connections configuration setting, which allows remote attackers to cause a denial of service (connection slot exhaustion) by making multiple connections and performing no operations on these connections, aka Bug Id 6648665.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sun ONE Directory Server | =6.1-enterprise | |
Sun ONE Directory Server | =6.3-enterprise | |
Sun ONE Directory Server | =6.2-enterprise | |
Sun ONE Directory Server | =6.3.1-enterprise | |
Sun ONE Directory Server | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-4442 is rated as a moderate severity vulnerability due to its potential for causing denial of service.
CVE-2009-4442 allows remote attackers to exhaust connection slots, leading to denial of service on affected versions of Sun Java System Directory Server.
CVE-2009-4442 affects Sun Java System Directory Server versions 6.0 through 6.3.1 inclusive.
To mitigate CVE-2009-4442, ensure proper configuration of the max-client-connections setting to limit the number of concurrent connections.
There are no specific patches mentioned for CVE-2009-4442; it's recommended to consult product documentation for guidance on updates.