vendor:
Enterprise Server
by:
Arne Vidstrom
7.5
CVSS
HIGH
Buffer Overflow
Unknown
CWE
Product Name: Enterprise Server
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE: Unknown
CPE: Unknown
Platforms Tested:
Unknown
Netscape Enterprise Server SSL Handshake Buffer Overflow
This program crashes Netscape Enterprise Server when it is running in SSL mode by exploiting a bug in the SSL handshake code. The server crashes if the client starts with SSL 2.0 format, uses a long record header, uses padding >= 8, sends at least 11 bytes more data than it specifies in the header, and sends at least about 4 kb data.
Mitigation:
Unknown