Sun Java System Calendar Server 6.3 - Duplicate URI Request Denial of Service

EDB-ID:

32860


Author:

SCS team

Type:

dos


Platform:

Java

Date:

2009-03-31


source: https://www.securityfocus.com/bid/34150/info

Sun Java System Calendar Server is prone to a denial-of-service vulnerability because it fails to handle certain duplicate URI requests.

An attacker can exploit this issue to crash the Calendar Server, resulting in a denial-of-service condition.

NOTE: Versions prior to Sun Java System Calendar Server 6.3 are not vulnerable. 

The following example data is available:

https://www.example.com:3443/?tzid=crash