OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Patrik Karlsson (patrik.karlssonse.pwcglobal.com)
Date: Wed May 08 2002 - 05:09:27 CDT

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    cqure.net Security Vulnerability Report
    No: cqure.net.20020412.netware_sdmr.a
    ========================================

    Vulnerability Summary
    ---------------------
    Problem: The IPX compatibility issue Posted to BugTraq on
                       July 11, 2000 by Dimuthu Parussalla applies to
                       Netware 6.0 SP 1 as well.

    Threat: An attacker could cause the SDMR.NLM to abend
                       and in some cases reboot the server. See bid
                       1467 for more information.

    Affected Software: Novell Netware 6.0 SP 1.

    Solution: Taken from Bugtraq bid 1467.
                       "IPX-Compatibility should not be enabled on
                       production servers."

    Solution
    --------
    Disable IPX-Compatibility on production servers.

    Additional Information
    ----------------------
    Novell was contacted 20020412.

    This vulnerability was found and researched by
    Patrik Karlsson & Jonas Ländin
    patrik.karlssonse.pwcglobal.com
    jonas.landinixsecurity.com

    This document is also available at: http://www.cqure.net/advisories/