Novell NetWare CIFS.NLM Denial of Service Vulnerability
BID:14701
Info
Novell NetWare CIFS.NLM Denial of Service Vulnerability
| Bugtraq ID: | 14701 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 31 2005 12:00AM |
| Updated: | Feb 01 2008 05:47PM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Novell Netware 6.5 SP3 Novell Netware 6.5 SP2 Novell Netware 6.0 SP3 Novell Netware 6.0 SP2 Novell Netware 6.0 SP1 Novell Netware 6.0 Novell Netware 5.1 SP6 Novell Netware 5.1 SP4 Novell Netware 5.1 SP5 Novell Netware 5.1 |
| Not Vulnerable: | |
Discussion
Novell NetWare CIFS.NLM Denial of Service Vulnerability
NetWare CIFS.NLM is prone to a remote denial-of-service vulnerability.
Reportedly, the W32.Randex.CCC worm can trigger this issue resulting in a denial-of-service condition due to an ABEND.
The following versions are vulnerable:
NetWare 5.1
NetWare 6.0
NetWare 6.5 SP2
NetWare 6.5 SP3
NetWare CIFS.NLM is prone to a remote denial-of-service vulnerability.
Reportedly, the W32.Randex.CCC worm can trigger this issue resulting in a denial-of-service condition due to an ABEND.
The following versions are vulnerable:
NetWare 5.1
NetWare 6.0
NetWare 6.5 SP2
NetWare 6.5 SP3
Exploit / POC
Novell NetWare CIFS.NLM Denial of Service Vulnerability
The malicious code termed W32.Randex.CCC can trigger this issue in NetWare.
The following exploit code is available as a module for the Metasploit Framework:
The malicious code termed W32.Randex.CCC can trigger this issue in NetWare.
The following exploit code is available as a module for the Metasploit Framework:
Solution / Fix
Novell NetWare CIFS.NLM Denial of Service Vulnerability
Solution:
Novell has released Technical Information Documents TID2971832, TID2971821, and TID2971822 to address this issue in supported versions of NetWare.
Novell Netware 5.1 SP4
Novell Netware 5.1 SP6
Novell Netware 5.1 SP5
Novell Netware 6.0 SP3
Novell Netware 6.0 SP2
Novell Netware 6.0 SP1
Novell Netware 6.5 SP3
Novell Netware 6.5 SP2
Solution:
Novell has released Technical Information Documents TID2971832, TID2971821, and TID2971822 to address this issue in supported versions of NetWare.
Novell Netware 5.1 SP4
-
Novell cifspt9.exe
http://support.novell.com/servlet/filedownload/sec/pub/cifspt9.exe
Novell Netware 5.1 SP6
-
Novell cifspt9.exe
http://support.novell.com/servlet/filedownload/sec/pub/cifspt9.exe
Novell Netware 5.1 SP5
-
Novell cifspt9.exe
http://support.novell.com/servlet/filedownload/sec/pub/cifspt9.exe
Novell Netware 6.0 SP3
-
Novell cifspt9.exe
http://support.novell.com/servlet/filedownload/sec/pub/cifspt9.exe
Novell Netware 6.0 SP2
-
Novell cifspt9.exe
http://support.novell.com/servlet/filedownload/sec/pub/cifspt9.exe
Novell Netware 6.0 SP1
-
Novell cifspt9.exe
http://support.novell.com/servlet/filedownload/sec/pub/cifspt9.exe
Novell Netware 6.5 SP3
-
Novell 65cifs22a.exe
http://support.novell.com/servlet/filedownload/sec/pub/65cifs22a.exe
Novell Netware 6.5 SP2
-
Novell 65cifs22nss2b.exe
http://support.novell.com/servlet/filedownload/sec/pub/65cifs22nss2b.e xe
References
Novell NetWare CIFS.NLM Denial of Service Vulnerability
References:
References: