SuSE Open Enterprise Server Novell Remote Manager HTTP Request Header Heap Overflow Vulnerability
BID:16226
Info
SuSE Open Enterprise Server Novell Remote Manager HTTP Request Header Heap Overflow Vulnerability
| Bugtraq ID: | 16226 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2005-3655 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 13 2006 12:00AM |
| Updated: | Jan 13 2006 12:00AM |
| Credit: | This issue was reported by iDEFENSE who credit an anonymous individual with discovering the issue. |
| Vulnerable: |
S.u.S.E. Open-Enterprise-Server 9.0 |
| Not Vulnerable: | |
Discussion
SuSE Open Enterprise Server Novell Remote Manager HTTP Request Header Heap Overflow Vulnerability
Novell Remote Manager (novell-nrm) is prone to a remotely exploitable heap overflow vulnerability. This issue may be triggered by a malicious HTTP request header.
Successful exploitation will allow for arbitrary code execution in the context of the application.
Novell Remote Manager ships with the SuSE Open Enterprise Server only.
Novell Remote Manager (novell-nrm) is prone to a remotely exploitable heap overflow vulnerability. This issue may be triggered by a malicious HTTP request header.
Successful exploitation will allow for arbitrary code execution in the context of the application.
Novell Remote Manager ships with the SuSE Open Enterprise Server only.
Exploit / POC
SuSE Open Enterprise Server Novell Remote Manager HTTP Request Header Heap Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
SuSE Open Enterprise Server Novell Remote Manager HTTP Request Header Heap Overflow Vulnerability
Solution:
The vendor has released advisory SUSE-SA:2006:002 has been released to address this issue. Updates may be installed through Red Carpet / ZLM. Please see the attached advisory for further information on obtaining and applying fixes.
Solution:
The vendor has released advisory SUSE-SA:2006:002 has been released to address this issue. Updates may be installed through Red Carpet / ZLM. Please see the attached advisory for further information on obtaining and applying fixes.
References
SuSE Open Enterprise Server Novell Remote Manager HTTP Request Header Heap Overflow Vulnerability
References:
References: