Description
Sun Java System Directory Proxy Server in Sun Java System Directory Server Enterprise Edition 6.0 through 6.3, when a JDBC data source is used, does not properly handle (1) a long value in an ADD or (2) long string attributes, which allows remote attackers to cause a denial of service (JDBC backend outage) via crafted LDAP requests.
Affected products
- sun / java_system_directory_server6.0 – 6.0
- sun / java_system_directory_server6.1 – 6.1
- sun / java_system_directory_server6.2 – 6.2
- sun / java_system_directory_server6.3 – 6.3