Novell Client SRVLOC.SYS Remote Denial of Service Vulnerability
BID:21430
Info
Novell Client SRVLOC.SYS Remote Denial of Service Vulnerability
| Bugtraq ID: | 21430 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 04 2006 12:00AM |
| Updated: | Dec 04 2006 09:54PM |
| Credit: | Tyler Krpata is credited with discovering this vulnerability. |
| Vulnerable: |
Novell Client 4.91 SP2 Novell Client 4.91 SP1 Novell Client 4.91 |
| Not Vulnerable: |
Novell Client 4.91 SP3 |
Discussion
Novell Client SRVLOC.SYS Remote Denial of Service Vulnerability
Novell Client is prone to a remote denial-of-service vulnerability because it fails to properly handle unexpected network traffic.
Successfully exploiting this issue allows remote attackers to crash affected computers, denying service to legitimate users.
Novell Client 4.91 is vulnerable; other versions may also be affected.
Novell Client is prone to a remote denial-of-service vulnerability because it fails to properly handle unexpected network traffic.
Successfully exploiting this issue allows remote attackers to crash affected computers, denying service to legitimate users.
Novell Client 4.91 is vulnerable; other versions may also be affected.
Exploit / POC
Novell Client SRVLOC.SYS Remote Denial of Service Vulnerability
Attackers likely use readily available network utilities to send crafted packets designed to trigger this issue.
Attackers likely use readily available network utilities to send crafted packets designed to trigger this issue.
Solution / Fix
Novell Client SRVLOC.SYS Remote Denial of Service Vulnerability
Solution:
Novell has released Service Pack 3 for Novell Client version 4.91 to address this issue. Please see the references for more information.
Solution:
Novell has released Service Pack 3 for Novell Client version 4.91 to address this issue. Please see the references for more information.
References
Novell Client SRVLOC.SYS Remote Denial of Service Vulnerability
References:
References:
- Denial of Service attack against srvloc.sys (Novell)
- Novell Homepage (Novell)