OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Peter Gründl (peter.grundlDEFCOM.COM)
Date: Tue Apr 03 2001 - 00:16:50 CDT

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    ======================================================================
                      Defcom Labs Advisory def-2001-17

                       Navision Financials Server DoS

    Author: Peter Gründl <peter.grundldefcom.com>
    Release Date: 2001-04-03
    ======================================================================
    ------------------------=[Brief Description]=-------------------------
    The Navision Financials Server contains a flaw that allows an attacker
    to crash the service.

    ------------------------=[Affected Systems]=--------------------------
    - Navision Financials Server V2.50 for Windows NT/2000
    - Navision Financials Server V2.60 for Windows NT/2000

    ----------------------=[Detailed Description]=------------------------
    Sending a null character followed by approx. 30k of A's to TCP port
    2407 causes a buffer overflow and terminates the process (SERVER.EXE).
    The overflow does not appear to be exploitable.

    A smaller amount can also be used, and will silently kill the process.
    This requires approx. 10 connections starting with a null character,
    followed by 100+ characters.

    ---------------------------=[Workaround]=-----------------------------
    Disallow access to TCP port 2407 from untrusted systems, and contact
    Navision-Damgaard Support to obtain the patch for this problem:

    http://www.navision.com/com/view.asp?documentID=258

    -------------------------=[Vendor Response]=--------------------------
    The issue was brought to the vendors attention on the 21st of
    December, 2000. A patch was created by the vendor on the 5th of March,
    2001.

    ======================================================================
                This release was brought to you by Defcom Labs

                  labsdefcom.com www.defcom.com
    ======================================================================