A bulletin released on May 29 by security group Next Generation Security Software warned of a new vulnerability in JRun Java 2 Enterprise Edition server that could allow an attacker to take control of a server. This affects users running JRun 3.1 on Microsoft's Internet Information Services (IIS) 4.0 and 5.0 on Windows NT 4 and Windows 2000. The group had contacted Macromedia about the bug in early April and Macromedia included a fix for the bug in JRun 4.0. Users have been urged to upgrade to the newest version of JRun.
Flaw in Macromedia JRun Could Let Attacker Take Over
CERT Advisory CA-2002-14 Buffer overflow in Macromedia JRun
Next Generation Security Software Advisory (#NISR29052002)
MPSB02-02-Patch Available for ISAPI buffer overflow in JRun 3.0/3.1