NOVL-2003-2966549 - Enterprise Web Server PERL Buffer Overflow

From: Ed Reed (ereed_at_novell.com)
Date: 07/23/03

  • Next message: advisory_at_rapid7.com: "R7-0015: Multiple Vulnerabilities Apple QuickTime/Darwin Streaming Server"
    Date: Wed, 23 Jul 2003 08:59:55 -0600
    To: "Secure Secure" <Secure@novell.com>
    
    

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    For Immediate Disclosure

    ============================== Summary ==============================

     Security Alert: NOVL-2003-2966549
              Title: Enterprise Web Server PERL Handler Buffer Overflow
               Date: 23-Jul-2003
           Revision: Original
       Product Name: Netware Enterprise Web Server
     OS/Platform(s): Netware 5.1, 6.0
      Reference URL: http://support.novell.com/servlet/tidfinder/2966549
        Vendor Name: Novell, Inc.
         Vendor URL: http://www.novell.com
    Security Alerts: http://support.novell.com/security-alerts
            Affects: cgi2perl.nlm
        Identifiers: CERT VU# 185593, CVE: CAN-2003-0562
            Credits: Uffe Nielsen

    ============================ Description ============================

    A Buffer Overflow in the PERL handler, (/perl/) may result in a
    server ABEND. The problem is not in the Netscape-based Enterprise
    Web Server, but in the Novell-supplied cgi2perl.nlm handler to PERL.

    ============================== Impact ===============================

    One or more server ABENDs may be triggered by buffer overflows,
    resulting in degraded performance or crash of the server, in turn
    causing in a denial of service to legitimate users of the system.
    There is no known ROOT shell exploit from this kind of failure on
    Netware.

    ======================== Recommended Actions ========================

    See detailed instructions in the referenced Technical Information
    Document (TID) http://support.novell.com/servlet/tidfinder/2966549.

    ============================ DISCLAIMER =============================

    The content of this document is believed to be accurate at the time
    of publishing based on currently available information. However, the
    information is provided "AS IS" without any warranty or
    representation. Your use of the document constitutes acceptance of
    this disclaimer. Novell disclaims all warranties, express or implied,
    regarding this document, including the warranties of merchantability
    and fitness for a particular purpose. Novell is not liable for any
    direct, indirect, or consequential loss or damage arising from use
    of, or reliance on, this document or any security alert, even if
    Novell has been advised of the possibility of such damages and even
    if such damages are foreseeable.

    ============================ Appendices =============================

    None

    ================ Contacting Novell Security Alerts ==================

    To report suspected security vulnerabilities in Novell products, send
    email to
                secure@novell.com

    or use the web form at our website

                http://support.novell.com/security-alerts

    PGP users may send signed/encrypted information to us using our PGP
    key, available from the pgpkeys.mit.edu server, or our website.

    Users wishing to be notified when Novell Security Alerts are issued
    may register their email address at

                http://www.novell.com/info/list/

    Security Alerts, Novell, Inc. PGP Key Fingerprint:

    F5AE 9265 0A34 F84E 580E 9B87 3AC1 1974 DE05 0FDB

    ========================= Revision History ==========================
           Original: 23-Jul-2003 - Original Publication

    -----BEGIN PGP SIGNATURE-----
    Version: PGP Personal Security 7.0.3

    iQA/AwUBPx5ssDrBGXTeBQ/bEQIVNwCg1XYO7F/Ddsl3V3QXo8WlYaogVDcAn1v0
    bRRR7anxwjvMOWpId5aC0Vwl
    =2sd0
    -----END PGP SIGNATURE-----


  • Next message: advisory_at_rapid7.com: "R7-0015: Multiple Vulnerabilities Apple QuickTime/Darwin Streaming Server"

    Relevant Pages

    • Re: Copy files from Novell with ASP.NET
      ... If you have permission on the web server box, try mapping a drive to the novell server and accessing it via it's drive letter. ...
      (microsoft.public.dotnet.framework.aspnet)
    • Re: Accessing Novell Netware volumes from Windows 2003 server
      ... Probably can't use mapped drives because the mapped drive is based on the ... The location on the Novell Server will have to allow *anonymous* access to ... on the Web Server and the passwords will have to be synced manually. ...
      (microsoft.public.win2000.networking)
    • Re: Need Recommendations on NT4 > WS2003 Migration
      ... actually running both Novell and NT authentication services? ... My main purpose in wanting to transfer the accounts is ... > user/group accounts manually on the new server... ...
      (microsoft.public.windows.server.migration)
    • Re: Accessing Novell Netware volumes from Windows 2003 server
      ... files I need from the Novell drive to my web server so they will be local to ... them in Word which is why they are currently on a Novell drive. ... This is actually a Windows 2003 issue, but I didn't know where best to ... see all the mapped Novell drives. ...
      (microsoft.public.win2000.networking)
    • Re: HP LaserJet 5L is streaking, how to clean up?
      ... RAID, mirroring, and tape backup are the road to hell. ... Novell clients to inform upon an impending shutdown so people could ... what files were open from the Novell server. ... Virus infected laptop. ...
      (sci.electronics.repair)