[VulnWatch] cqure.net.20020604.netware_dhcpsrvr

From: Patrik Karlsson (patrik@cqure.net)
Date: 06/25/02


Date: Tue, 25 Jun 2002 18:49:33 -0100 (GMT+1)
From: Patrik Karlsson <patrik@cqure.net>
To: vulnwatch@vulnwatch.org

cqure.net Security Vulnerability Report
No: cqure.net.20020604.netware_dhcpsrvr
=======================================

Vulnerability Summary
---------------------
Problem: The Netware DHCP server has a DOS
                        vulnerability.

Threat: An attacker could cause the Netware server
                        to reboot, simple by issueing a
                        "non-standard" dhcp request.

Affected Software: Novell Netware FTP server.

Platforms: Netware 6.0 verified SP 1.

Solutions: Install patches from Novell as soon as
                        they become available.

Vulnerability Description
-------------------------
The DHCP server suffers from multiple bufferoverflows which can be
triggered by sending oversized "non-standard" requests to the DHCP
server.

Additional Information
----------------------
Novell was contacted 20020604.

This vulnerability was found by
Patrik Karlsson & Jonas Ländin
patrik@cqure.net
jonas@cqure.net

This document is also available at: http://www.cqure.net/advisories/



Relevant Pages

  • SecurityFocus Microsoft Newsletter #142
    ... MICROSOFT VULNERABILITY SUMMARY ... Mollensoft Enceladus Server Suite Clear Text Password Storage... ... FakeBO Syslog Format String Vulnerability ... Methodus 3 Web Server File Disclosure Vulnerability ...
    (Focus-Microsoft)
  • SecurityFocus Microsoft Newsletter #139
    ... OFF any Windows 2000 Managed Dedicated Hosting Solution from Interland. ... Sun ONE Application Server Plaintext Password Vulnerability ... Batalla Naval Remote Buffer Overflow Vulnerability ...
    (Focus-Microsoft)
  • SecurityFocus Microsoft Newsletter #140
    ... Cafelog b2 Remote File Include Vulnerability ... Webfroot Shoutbox Remote Command Execution Vulnerability ... Pablo Software Solutions Baby POP3 Server Multiple Connection... ... Microsoft Windows XP Nested Directory Denial of Service... ...
    (Focus-Microsoft)
  • SecurityFocus Microsoft Newsletter # 150
    ... - automatically set positive security policies for real-time protection, ... MICROSOFT VULNERABILITY SUMMARY ... Meteor FTP Server USER Memory Corruption Vulnerability ... MDaemon SMTP Server Null Password Authentication Vulnerabili... ...
    (Focus-Microsoft)
  • SecurityFocus Microsoft Newsletter #152
    ... MICROSOFT VULNERABILITY SUMMARY ... Real Networks Helix Universal Server Remote Buffer Overflow ... ... NEW PRODUCTS FOR MICROSOFT PLATFORMS ...
    (Focus-Microsoft)