Netware Remote Manager Authentication Buffer Overflow Vulnerability
BID:4405
Info
Netware Remote Manager Authentication Buffer Overflow Vulnerability
| Bugtraq ID: | 4405 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 02 2002 12:00AM |
| Updated: | Apr 02 2002 12:00AM |
| Credit: | Discovered by Patrik Karlsson <[email protected]> and Jonas Ländin <[email protected]>. |
| Vulnerable: |
Novell Netware 6.0 Novell Netware 5.1 |
| Not Vulnerable: | |
Discussion
Netware Remote Manager Authentication Buffer Overflow Vulnerability
Novell Netware Remote Manager provides a web based administrative interface for the Novell product. The Remote Manager accepts SSL connections on port 8009 by default.
If a HTTP Basic Authentication request is sent with extremely long values for the username or password field, a buffer overflow will occur. Depending on the length of the string submitted, either the SERVER.NLM or the HTTPSTK.NLM process will halt with an ABEND error, resulting in a denial of service condition.
It may prove possible to execute arbitrary code as the server process. This has not, however, been confirmed.
Novell Netware Remote Manager provides a web based administrative interface for the Novell product. The Remote Manager accepts SSL connections on port 8009 by default.
If a HTTP Basic Authentication request is sent with extremely long values for the username or password field, a buffer overflow will occur. Depending on the length of the string submitted, either the SERVER.NLM or the HTTPSTK.NLM process will halt with an ABEND error, resulting in a denial of service condition.
It may prove possible to execute arbitrary code as the server process. This has not, however, been confirmed.
Exploit / POC
Netware Remote Manager Authentication Buffer Overflow Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Netware Remote Manager Authentication Buffer Overflow Vulnerability
Solution:
A fix is available:
Novell Netware 5.1
Novell Netware 6.0
Solution:
A fix is available:
Novell Netware 5.1
-
Novell httpstk1.exe
http://support.novell.com/servlet/filedownload/pub/httpstk1.exe/
Novell Netware 6.0
-
Novell httpstk1.exe
http://support.novell.com/servlet/filedownload/pub/httpstk1.exe/
References
Netware Remote Manager Authentication Buffer Overflow Vulnerability
References:
References:
- HTTPSTK Vulnerability Fix (Novell)