Novell Client Denial of Service Vulnerability
BID:700
Info
Novell Client Denial of Service Vulnerability
| Bugtraq ID: | 700 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 08 1999 12:00AM |
| Updated: | Oct 08 1999 12:00AM |
| Credit: | Posted to BugTraq by Bruce Dennison <[email protected]> on October 8, 1999. |
| Vulnerable: |
Novell Client 3.0.1 Novell Client 3.0 |
| Not Vulnerable: | |
Discussion
Novell Client Denial of Service Vulnerability
Novell client versions 3.0 and 3.01 for Windows platforms are vulnerable to a remotely exploitable vulnerability which could cause a denial of service. The client opens a listening tcp socket on port 427, to which if a SYN is sent, results in the machine locking with a "blue screen" error. The only solution from that point is to reset the affected computer.
Novell client versions 3.0 and 3.01 for Windows platforms are vulnerable to a remotely exploitable vulnerability which could cause a denial of service. The client opens a listening tcp socket on port 427, to which if a SYN is sent, results in the machine locking with a "blue screen" error. The only solution from that point is to reset the affected computer.
Exploit / POC
Novell Client Denial of Service Vulnerability
nmap -sS -p 427 <target>
nmap -sS -p 427 <target>