FUJITSU

  1. Home >
  2. Support & Downloads >
  3. Software >
  4. Security >
  5. Fujitsu Patch & TA Information >
  6. This page provides Security Information.

Denial of service (DoS) and cross-site scripting (XSS) vulnerabilities in Interstage HTTP Server June 5th, 2006


Notes on using this web page

1. Background and Detected problem(s)

The following 3 security vulnerabilities were discovered in the Interstage HTTP Server included in Interstage Application Server and Interstage Apworks.

  1. Denial of service (DoS) vulnerability in operation using SSL.
  2. Cross-site scripting vulnerability when using the image map function.
    This vulnerability corresponds to CVE-2005-3352.
  3. Denial of service (DoS) and arbitrary code execution vulnerabilities in the online collation function.
    This vulnerability corresponds to CVE-2006-0150.

Fujitsu provides security patches shown in 3.
Please apply them as soon as possible.

2. Method to temporarily avoid the problem

None.

3. Corresponding system and Patch information

Corresponding system : GP7000F, PRIMEPOWER, PRIMERGY, GP5000, CELSIUS, FMV, PRIMEQUEST

Products Target OS Package name Patch ID.
Interstage Application Server Enterprise Edition V5.0 for Windows Windows F3FMihs download dataTP08431(TP08431.exe: 778KB)
Interstage Application Server Standard Edition V5.0 for Windows Windows F3FMihs download dataTP08431(TP08431.exe: 778KB)
Interstage Application Server Web-J Edition V5.0 for Windows Windows F3FMihs download dataTP08431(TP08431.exe: 778KB)
Interstage Application Server Plus V5.0.1 for Windows Windows F3FMihs -
Interstage Application Server Plus Developer V5.0.1 for Windows Windows F3FMihs -
Interstage Application Server Enterprise Edition V6.0 for Windows Windows F3FMihs -
Interstage Application Server Plus V6.0 for Windows Windows F3FMihs -
Interstage Application Server Plus Developer V6.0 for Windows Windows F3FMihs -
Interstage Application Server Enterprise Edition V7.0 for Windows Windows F3FMihs download dataTP38431(TP38431G.exe: 313KB)
Interstage Application Server Plus V7.0 for Windows Windows F3FMihs download dataTP38431(TP38431G.exe: 313KB)
Interstage Application Server Plus Developer V7.0 for Windows Windows F3FMihs download dataTP38431(TP38431G.exe: 313KB)
Interstage Application Server Enterprise Edition V7.0.1 for Windows Windows F3FMihs download dataTP38431(TP38431G.exe: 313KB)
Interstage Application Server Plus V7.0.1 for Windows Windows F3FMihs download dataTP38431(TP38431G.exe: 313KB)
Interstage Apworks Modelers-J Edition V6.0 for Windows Windows F3FMihs -
Interstage Apworks Modelers-J Edition V6.0A for Windows Windows F3FMihs -
Interstage Apworks Modelers-J Edition V7.0 for Windows Windows F3FMihs download dataTP38431(TP38431G.exe: 313KB)
Interstage Application Server Enterprise Edition 5.0 Solaris FJSVihs download data912327-08(912327-08.tar.Z: 884KB)
Interstage Application Server Standard Edition 5.0 Solaris FJSVihs download data912327-08(912327-08.tar.Z: 884KB)
Interstage Application Server Web-J Edition 5.0 Solaris FJSVihs download data912327-08(912327-08.tar.Z: 884KB)
Interstage Application Server Enterprise Edition 5.0.1 Solaris FJSVihs -
Interstage Application Server Enterprise Edition 6.0 Solaris FJSVihs -
Interstage Application Server Enterprise Edition 7.0 Solaris FJSVihs download dataT013RS-03(INTS-APSREE7.0_PUF_T013RS-03.tar.Z: 459KB)
Interstage Application Server Plus 7.0 Solaris FJSVihs download dataT013RS-03(INTS-APSREE7.0_PUF_T013RS-03.tar.Z: 459KB)
Interstage Application Server Enterprise Edition 7.0.1 Solaris FJSVihs download dataT023AS-01(INTS-APSREE7.0.1_PUF_T023AS-01.tar.Z: 396KB)
Interstage Application Server Plus 7.0.1 Solaris FJSVihs download dataT023AS-01(INTS-APSREE7.0.1_PUF_T023AS-01.tar.Z: 396KB)
Interstage Application Server Enterprise Edition V5.0 * Turbolinux 7 Server FJSVihs T00019-07
Interstage Application Server Standard Edition V5.0 * Turbolinux 7 Server FJSVihs T00019-07
Interstage Application Server Web-J Edition V5.0 * Turbolinux 7 Server FJSVihs T00019-07
Interstage Application Server Enterprise Edition V6.0 * RHEL-AS3(x86)/ES3(x86) FJSVihs -
Interstage Application Server Enterprise Edition V7.0 RHEL-AS4(IPF) FJSVihs -
Interstage Application Server Enterprise Edition V7.0 RHEL-AS3(x86)/ES3(x86) FJSVihs T00603-02
Interstage Application Server Plus V7.0 RHEL-AS3(x86)/ES3(x86) FJSVihs T00603-02
Interstage Application Server Enterprise Edition V7.0.1 RHEL-AS3(x86)/ES3(x86)/AS4(x86) FJSVihs T00603-02
Interstage Application Server Plus V7.0.1 RHEL-AS3(x86)/ES3(x86)/AS4(x86) FJSVihs T00603-02

Note) The products described with * are not vulnerable to 3), because online collation function is not supported.
For the Patches without ID or link, please contact a Fujitsu system engineer.

4. Revision history

  • June 5th, 2006 : Initial release