[NEWS] Buffer Overflows in Novell iChain Authentication
From: SecuriTeam (support_at_securiteam.com)
Date: 06/09/03
- Previous message: SecuriTeam: "[NEWS] XSS Vulnerability in Synkron.web CMS"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
To: list@securiteam.com Date: 9 Jun 2003 18:45:40 +0200
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
Latest attack techniques.
You're a pen tester, but is google.com still your R&D team?
Now you can get trustworthy commercial-grade exploits and the latest
techniques from a world-class research group.
Learn more at http://www.coresecurity.com/promos/sit_e1,
or call 617-399-6980
- - - - - - - - -
Buffer Overflows in Novell iChain Authentication
------------------------------------------------------------------------
SUMMARY
The Novell iChain product provides identity-based web security services
that control access to application and network resources across technical
and organizational boundaries.
Buffer overflows allow users without authenticating to crash the iChain
Server. Due to the nature of the overflow, it is likely that this can lead
to remote administrative access to the server and thus full access to the
protected networks.
DETAILS
Affected products:
* Novell iChain Server 2.1 SP2
* Novell iChain Server 2.2
* Novell iChain Server 2.2 incl. Field Patch 1 (see details)
The length of the username is only restricted by the SIZE parameter in the
HTML forms but not in the iChain proxy itself. This can be exploited
easily by sending an overly long username in the authentication dialog
that causes the iChain Server to abend (freeze).
In iChain 2.2 Field Patch 1 the username has to be at the end of the POST
parameter list, otherwise iChain only prompts with a message stating
missing parameters.
Although we are not aware of any exploits in the wild it seems sure that
this is being used to gain access in any targeted attack since this
vulnerability can be found and exploited easily.
Fixes & Workarounds:
Novell developed patches ic22fp1a.exe (for iChain 2.2) and ic21fp3.exe
(for iChain 2.1), available today on Novell's support Web site at
<http://support.novell.com/filefinder>
http://support.novell.com/filefinder.
ADDITIONAL INFORMATION
The information has been provided by <mailto:security@Dunkel.de> Axel
Dunkel.
========================================
This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com
====================
====================
DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
- Previous message: SecuriTeam: "[NEWS] XSS Vulnerability in Synkron.web CMS"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
- [Full-Disclosure] Buffer Overflows in Novell iChain Authentication
... The Novell iChain product provides identity-based web security ... services
that control access to application and network resources ... Novell iChain Server
2.1 SP2 ... (Full-Disclosure) - [Full-Disclosure] Buffer Overflows in Novell iChain (Patches available)
... The Novell iChain product provides identity-based web security ... services
that control access to application and network resources ... Novell iChain Server
2.1 SP2 ... (Full-Disclosure)