Korean
<< Back
VID 22339
Severity 30
Port 80, ...
Protocol TCP
Class WWW
Detailed Description The Jetty HTTP server, according to its banner, has a denial of service vulnerability. Jetty is an open-source based Java HTTP Server and Servlet Engine. Jetty versions prior to 4.2.19 are vulnerable to an unspecified denial of service vulnerability, which may be exploited remotely.

* Note: This check solely relied on the banner of the remote HTTP server to assess this vulnerability, so this might be a false positive.

* References:
http://secunia.com/advisories/11166/

* Platforms Affected:
Jetty Project, Jetty versions prior to 4.2.19
Linux Any version
Unix Any version
Recommendation Upgrade to the latest version of Jetty (4.2.19 or later), available from the Jetty Web site at http://download.eclipse.org/jetty/
Related URL CVE-2004-2381 (CVE)
Related URL 9917 (SecurityFocus)
Related URL 15537 (ISS)