[3/5] Hitachi Cosminexus JSSE SSL/TLS Handshake Denial of Service
:A vulnerability has been reported in Hitachi Cosminexus, which can be exploited by malicious people to cause a DoS (Denial of Service).The vulnerability is caused due to an error in the JSSE (Java Secure Socket Extension) of Cosminexus Developer’s Kit for Java(TM) when handling invalid SSL/TLS handshake requests. This can be exploited to cause a DoS on an affected system that uses JSEE APIs to handle SSL/TLS connections.This may be related to vulnerability #1 in:SA26015The vulnerability affects Cosminexus version 7.5 (see vendor’s advisory for details).Solution:Please see the vendor’s advisory for fix details.Provided and/or discovered by:Reported by the vendor.Original Advisory:http://www.hitachi-support.com/security_e/vuls_e/HS07-031_e/index-e.htmlOther References:SA26015:http://secunia.com/advisories/26015/
Original post by Pankaj
Posted in Advisories - Exploits |
| [3/5] Hitachi Cosminexus JSSE SSL/TLS Handshake Denial of Service