Novell iChain Server Remote Authentication Username Buffer Overrun Vulnerability
BID:7839
Info
Novell iChain Server Remote Authentication Username Buffer Overrun Vulnerability
| Bugtraq ID: | 7839 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 06 2003 12:00AM |
| Updated: | Jun 06 2003 12:00AM |
| Credit: | The discovery of this vulnerability has been credited to "Axel Dunkel" <[email protected]>. |
| Vulnerable: |
Novell iChain Server 2.2 FP1 Novell iChain Server 2.2 Novell iChain Server 2.1 SP2 Novell iChain Server 2.1 SP1 Novell iChain Server 2.1 |
| Not Vulnerable: |
Novell iChain Server 2.2 FP1a |
Discussion
Novell iChain Server Remote Authentication Username Buffer Overrun Vulnerability
A vulnerability has been discovered in Novell iChain Server. The problem occurs due to insufficient bounds checking when reading in a username supplied during authentication. As a result, an attacker may be capable of triggering a buffer overrun by supplying a username of excessive length.
Successful exploitation of this vulnerability has been confirmed to trigger a denial of service. Although it has not been confirmed, it has been speculated that this issue can be exploited to execute arbitrary code.
A vulnerability has been discovered in Novell iChain Server. The problem occurs due to insufficient bounds checking when reading in a username supplied during authentication. As a result, an attacker may be capable of triggering a buffer overrun by supplying a username of excessive length.
Successful exploitation of this vulnerability has been confirmed to trigger a denial of service. Although it has not been confirmed, it has been speculated that this issue can be exploited to execute arbitrary code.
Solution / Fix
Novell iChain Server Remote Authentication Username Buffer Overrun Vulnerability
Solution:
Novell has released new field patches to address this issue for iChain Server 2.1 and 2.2.
Novell iChain Server 2.1 SP1
Novell iChain Server 2.1 SP2
Novell iChain Server 2.1
Novell iChain Server 2.2
Novell iChain Server 2.2 FP1
Solution:
Novell has released new field patches to address this issue for iChain Server 2.1 and 2.2.
Novell iChain Server 2.1 SP1
-
Novell ic21fp3.exe
http://support.novell.com/servlet/filedownload/ftf/ic21fp3.exe/
Novell iChain Server 2.1 SP2
-
Novell ic21fp3.exe
http://support.novell.com/servlet/filedownload/ftf/ic21fp3.exe/
Novell iChain Server 2.1
-
Novell ic21fp3.exe
http://support.novell.com/servlet/filedownload/ftf/ic21fp3.exe/
Novell iChain Server 2.2
-
Novell ic22fp1a.exe
http://support.novell.com/servlet/filedownload/ftf/ic22fp1a.exe/
Novell iChain Server 2.2 FP1
-
Novell ic22fp1a.exe
http://support.novell.com/servlet/filedownload/ftf/ic22fp1a.exe/
References
Novell iChain Server Remote Authentication Username Buffer Overrun Vulnerability
References:
References: