[NEWS] Novell Netware Client Unchecked Buffers
From: support@securiteam.comDate: 05/08/02
- Previous message: support@securiteam.com: "[NEWS] Novell SDMR DoS"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: support@securiteam.com To: list@securiteam.com Date: Wed, 8 May 2002 18:13:09 +0200 (CEST)
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
When was the last time you checked your server's security?
How about a monthly report?
http://www.AutomatedScanning.com - Know that you're safe.
- - - - - - - - -
Novell Netware Client Unchecked Buffers
------------------------------------------------------------------------
SUMMARY
Multiple Buffer Overflow Conditions Exist in the Novell Netware Client for
Windows. An attacker could crash any software relying on name resolution,
like ping, traceroute, rexec and rsh.
DETAILS
Vulnerable systems:
* Novell Netware Client 4.83
If one would run the command ping with a long hostname an access violation
would occur. Depending on the length of the hostname the program will
crash in different locations. This might be interesting in a WTS or Citrix
environment. We have looked very briefly at the problem and therefore
cannot comment on the impact of this issue.
Solution:
Install patch from Novell as soon as it becomes available.
Vendor status:
Novell was contacted 20020412.
ADDITIONAL INFORMATION
The information has been provided by
<mailto:patrik.karlsson@se.pwcglobal.com> Patrik Karlsson &
<mailto:jonas.landin@ixsecurity.com> Jonas Ländin.
========================================
This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com
====================
====================
DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
- Previous message: support@securiteam.com: "[NEWS] Novell SDMR DoS"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]