CERT-In Vulnerability Note
CIVN-2014-0281
Denial-of-Service Vulnerability in Adobe ColdFusion
Original Issue Date:December 10, 2014
Severity Rating: MEDIUM
Component Affected
Overview
A vulnerability has been reported in Adobe ColdFusion which could be exploited by a remote attacker to conduct denial of service conditions on the target system.
Description
The vulnerability is due to resource consumption issue in Adobe ColdFusion. A remote attacker could successfully exploit this vulnerability by gaining unauthorized access to files on a vulnerable system.
Successful exploitation of this vulnerability could allow a remote attacker to conduct denial of service conditions on the affected system.
Solution
Apply appropriate patches as mentioned in
APSB14-29
Vendor Information
Adobe
http://helpx.adobe.com/security/products/coldfusion/apsb14-29.html
References
Adobe
http://helpx.adobe.com/security/products/coldfusion/apsb14-29.html
Security Tracker
http://www.securitytracker.com/id/1031321
CVE Name
CVE-2014-9166
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|