Symantec Ghost Configuration Server DoS Attack
BID:2570
Info
Symantec Ghost Configuration Server DoS Attack
| Bugtraq ID: | 2570 |
| Class: | Input Validation Error |
| CVE: |
CVE-2001-0598 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 11 2001 12:00AM |
| Updated: | Jul 11 2009 06:06AM |
| Credit: | Discovered by Peter Gründl <[email protected]> and posted to Bugtraq on April 11, 2001. |
| Vulnerable: |
Symantec Ghost Corporate Edition 6.5 |
| Not Vulnerable: | |
Exploit / POC
Symantec Ghost Configuration Server DoS Attack
Supplying a character string consisting of approximately 45 kilobytes over port 1347 will cause Symantec Ghost to cease functioning.
Supplying a character string consisting of approximately 45 kilobytes over port 1347 will cause Symantec Ghost to cease functioning.
Solution / Fix
Symantec Ghost Configuration Server DoS Attack
Solution:
Symantec has rectified this issue with the release of Ghost version 7.0. Upgrades to 7.0 are free for those who purchased Upgrade Insurance as part of their license. Direct all inquiries to:
http://www.symantec.com/ghost
and/or
http://www.binaryresearch.net
Solution:
Symantec has rectified this issue with the release of Ghost version 7.0. Upgrades to 7.0 are free for those who purchased Upgrade Insurance as part of their license. Direct all inquiries to:
http://www.symantec.com/ghost
and/or
http://www.binaryresearch.net