| By ColdFusion News Desk | Article Rating: |
|
| August 20, 2009 11:45 AM EDT | Reads: |
8,855 |
Critical vulnerabilities have been identified in ColdFusion v8.0.1 and earlier versions, and JRun 4.0. Adobe has now patched them with a Security Update released on August 17, 2009.
Here are the details, direct from Adobe's own Security Bulletin:
"Summary
Critical vulnerabilities have been identified in ColdFusion v8.0.1 and earlier versions, and JRun 4.0. These vulnerabilities could lead to the potential compromise of user accounts or the affected system.
Affected software versions
ColdFusion 8.0.1 and earlier versions
JRun 4.0
Solution
Adobe recommends affected ColdFusion and JRun customers update their installations using the links in the Details section below.
Severity rating
Adobe categorizes these as critical issues and recommends affected users patch their installations.
Details
Critical vulnerabilities have been identified in ColdFusion v8.0.1 and earlier versions, and JRun 4.0. These vulnerabilities could lead to the potential compromise of user accounts or the affected system.
An update for ColdFusion resolves a cross-site scripting vulnerability that could potentially lead to code execution (CVE-2009-1872).
An update for ColdFusion resolves a cross-site scripting vulnerability that could potentially lead to code execution (CVE-2009-1877).
ColdFusion users can find the appropriate links to fix CVE-2009-1872 and CVE-2009-1877 here:
• Installation instructions for CVE-2009-1872 and CVE-2009-1877
• CVE-2009-1872 and CVE-2009-1877 Hotfix for ColdFusion 7.0.2
• CVE-2009-1872 and CVE-2009-1877 Hotfix for ColdFusion 8
• CVE-2009-1872 and CVE-2009-1877 Hotfix for ColdFusion 8.0.1
An update for JRun resolves a management console directory traversal vulnerability that could potentially lead to information disclosure (CVE-2009-1873).
An update for JRun resolves multiple management console cross-site scripting vulnerabilities that could potentially lead to code execution (CVE-2009-1874).
JRun users can find the appropriate links to fix CVE-2009-1873 and CVE-2009-1874 here:
• Installation instructions for CVE-2009-1873 and CVE-2009-1874
• CVE-2009-1873 and CVE-2009-1874 Hotfix for JRun 4.0
An update for ColdFusion resolves multiple cross-site scripting vulnerabilities that could potentially lead to code execution (CVE-2009-1875).
ColdFusion users can find the appropriate links to fix CVE-2009-1875 here:
• Installation instructions for CVE-2009-1875
• CVE-2009-1875 Hotfix for ColdFusion 7.0.2, and hf702-1875.jar Hotfix for ColdFusion 7.0.2
• CVE-2009-1875 Hotfix for ColdFusion 8, and hf800-1875.jar Hotfix for ColdFusion 8
• CVE-2009-1875 Hotfix for ColdFusion 8.0.1, and hf801-1875.jar Hotfix for ColdFusion 8.0.1
An update for ColdFusion resolves a double-encoded null character vulnerability that could potentially lead to information disclosure (CVE-2009-1876).
ColdFusion users can find the appropriate links to fix CVE-2009-1876 here:
• Installation instructions for CVE-2009-1876
• CVE-2009-1876 Hotfix for ColdFusion
An update for ColdFusion resolves a session fixation vulnerability that could potentially lead to privilege escalation (CVE-2009-1878).
ColdFusion users can find the appropriate links to fix CVE-2009-1878 here:
• Installation instructions for CVE-2009-1878
• CVE-2009-1878 hf702-1878.jar Hotfix for ColdFusion 7.0.2
• CVE-2009-1878 hf800-1878.jar Hotfix for ColdFusion 8
• CVE-2009-1878 hf801-1878.jar Hotfix for ColdFusion 8.0.1
Acknowledgments
Adobe would like to thank the following individuals and organizations for reporting the relevant issues and for working with Adobe to help protect our customers’ security.
- Alexandr Polyakov of Digital Security (CVE-2009-1872, CVE-2009-1873, CVE-2009-1874)
- Chad Horton of SecurityMetrics (CVE-2009-1876)
- Pete Freitag of Foundeo Inc. (CVE-2009-1877)
- Jason Dean of 12 Robots (CVE-2009-1878)"
Published August 20, 2009 Reads 8,855
Copyright © 2009 SYS-CON Media, Inc. — All Rights Reserved.
Syndicated stories and blog feeds, all rights reserved by the author.
More Stories By ColdFusion News Desk
CFDJ News Desk monitors the world of ColdFusion to present developers with updates on technology advances, new features and performance enhancements concerning ColdFusion, business trends, ColdFusion-related products, standards discussions, and industry commentary.
- Acquia Announces Two New Board Members
- CollabNet Adds Board Member and Senior Executives to Fuel Continued Growth in Agile ALM and Enterprise Cloud Development
- Learn Open Source Database Tools from Stanford for Free
- Research and Markets: Global Mobile Device Management Enterprise Software Market 2010-2014 Includes a Discussion of the Key Vendors Operating in This Market
- Alternative Search Engines for the Contemporary User
- FORTUNE Magazine Names Rackspace Among “100 Best Companies to Work For”
- New York City : Blueprint for Cloud-enabled economic transformation
- EnterpriseDB Announces Availability of Postgres Plus Cloud Database
- Connectria Hosting Achieves "Off the Chart" Operational Efficiency With Cloud-Based Storage Solution From Nexsan and CommVault
- ICOS and Joyent Announce Strategic Partnership to Deliver Joyent's Cloud Infrastructure Solution to Channel Partners and Service Providers
- eXo Platform 3.5 Now Available: First Cloud-Ready Enterprise Portal and User Experience Platform-as-a-Service (UXPaaS)
- Research and Markets: WordPress 24-Hour Trainer, 2nd Edition
- Five Years Waiting for JRE 7: Is It Justified? (Part 1)
- Book Review: The CERT Oracle Secure Coding Standard for Java
- Acquia Announces Two New Board Members
- CollabNet Adds Board Member and Senior Executives to Fuel Continued Growth in Agile ALM and Enterprise Cloud Development
- Learn Open Source Database Tools from Stanford for Free
- China suppliers of mobile phones expand range with more smartphone and 3G models
- Research and Markets: Global Mobile Device Management Enterprise Software Market 2010-2014 Includes a Discussion of the Key Vendors Operating in This Market
- Government Big Data Solutions Award Nominee: Wayne Wheeles (Sherpa Surfing)
- Alternative Search Engines for the Contemporary User
- FORTUNE Magazine Names Rackspace Among “100 Best Companies to Work For”
- New York City : Blueprint for Cloud-enabled economic transformation
- EnterpriseDB Announces Availability of Postgres Plus Cloud Database
- Java Developer's Journal Exclusive: 2006 "JDJ Editors' Choice" Awards
- The i-Technology Right Stuff
- Creating Web Applications with the Eclipse Web Tools Project
- Eclipse Special: Remote Debugging Tomcat & JBoss Apps with Eclipse
- The Next Programming Models, RIAs and Composite Applications
- Where Are RIA Technologies Headed in 2008?
- SYS-CON Webcast: Eclipse IDE for Students, Useful Eclipse Tips & Tricks
- How to Bring Eclipse 3.1, J2SE 5.0, and Tomcat 5.0 Together
- Eclipse: The Story of Web Tools Platform 0.7
- "Eclipse 3.0 is a Great Leap Forward," Says JDJ's Dudney
- The Top 250 Players in the Cloud Computing Ecosystem
- Developing an Eclipse BIRT Report Item Extension




















