ColdFusion syntax checker can cause a system to use all processor resources

Risk Level: Medium risk vulnerability  Medium

Check or Attack Name: ColdFusionSyntaxChecker

Platforms: Cold Fusion
Description:

The Syntax Checker is a program shipped with ColdFusion with the purpose of testing older CFML code for compatibility with version 4. A vulnerability in this program allows remote attackers to cause the system to consume all available processor resources.

Remedy:

Upgrade to ColdFusion 4.0.1 once it becomes available. It is recommended users remove the "cfmlsyntaxcheck.cfm" program from all production servers.

References:

Allaire Security Bulletin ASB99-02, ColdFusion 4.0 Example Applications and Sample Code Exposes Servers, http://www.allaire.com/handlers/index.cfm?ID=8739&Method=Full


X-Force Logo
Know Your Risks