Jana Server contains a buffer overflow in the HTTP server. If an extremely long HTTP request is received, the server will crash when attempting to log the request.
Classification
Location:
Remote / Network Access
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
OSVDB:
Web Related
Solution
There have been no official patches released to correct this issue. As a work around, administrators may wish to disable HTTP logging. This may, however, allow other attacks or errors to go undetected.