A remote overflow exists in JRun, ColdFusion MX and ColdFusion MX J2EE - JRun. They fail to properly check boundaries in the verbose logging module resulting in a buffer overflow. With a specially crafted request, an attacker can cause a DoS resulting in a loss of availability.
Classification
Location:
Remote/Network Access Required
Attack Type:
Denial of Service,
Input Manipulation
Impact:
Loss of Availability
Exploit:
Exploit Unknown
Disclosure:
OSVDB Verified
Solution
Macromedia, Inc. has released a patch to address this vulnerability. As a workaround, disable the verbose debug mode.