Multiple Novell iChain Buffer Overflow Vulnerabilities
BID:8280
Info
Multiple Novell iChain Buffer Overflow Vulnerabilities
| Bugtraq ID: | 8280 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 25 2003 12:00AM |
| Updated: | Jul 25 2003 12:00AM |
| Credit: | These vulnerabilities have been announced in a Novell technical description document. |
| Vulnerable: |
Novell iChain Server 2.1 SP2 Novell iChain Server 2.1 SP1 Novell iChain Server 2.1 |
| Not Vulnerable: |
Novell iChain Server 2.1 SP3 |
Discussion
Multiple Novell iChain Buffer Overflow Vulnerabilities
Novell iChain has been reported prone to multiple buffer overflow vulnerabilities.
The first issue occurs when a special script is run against login. It is reported that this issue may be exploited to trigger a server ABEND condition.
The second issue occurs when excessive data is passed as a user login name to the iChain server. Under certain circumstances, the excessive data will likely trigger an ABEND condition in the affected software.
Novell iChain has been reported prone to multiple buffer overflow vulnerabilities.
The first issue occurs when a special script is run against login. It is reported that this issue may be exploited to trigger a server ABEND condition.
The second issue occurs when excessive data is passed as a user login name to the iChain server. Under certain circumstances, the excessive data will likely trigger an ABEND condition in the affected software.
Exploit / POC
Multiple Novell iChain Buffer Overflow Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Multiple Novell iChain Buffer Overflow Vulnerabilities
Solution:
The vendor has released a service pack to address these and other issues, it should be noted that a valid Novell site session id is required to view this link:
Novell iChain Server 2.1 SP2
Solution:
The vendor has released a service pack to address these and other issues, it should be noted that a valid Novell site session id is required to view this link:
Novell iChain Server 2.1 SP2
-
Novell ic21sp3.exe
http://support.novell.com/cgi-bin/search/searchtid.cgi?/2966560.htm
References
Multiple Novell iChain Buffer Overflow Vulnerabilities
References:
References: