ColdFusion syntax checker can cause a system to use all processor resources |
---|
Risk Level: | Medium | Check or Attack Name: ColdFusionSyntaxChecker |
---|---|---|
Platforms: | Cold Fusion | |
Description: | The Syntax Checker is a program shipped with ColdFusion with the purpose of testing older CFML code for compatibility with version 4. A vulnerability in this program allows remote attackers to cause the system to consume all available processor resources. |
|
Remedy: | Upgrade to ColdFusion 4.0.1 once it becomes available. It is recommended users remove the "cfmlsyntaxcheck.cfm" program from all production servers. |
|
References: | Allaire Security Bulletin ASB99-02, ColdFusion 4.0 Example Applications and Sample Code Exposes Servers, http://www.allaire.com/handlers/index.cfm?ID=8739&Method=Full |
Know Your Risks |