Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Netware Remote Manager Authentication Buffer Overflow Vulnerability

Novell Netware Remote Manager provides a web based administrative interface for the Novell product. The Remote Manager accepts SSL connections on port 8009 by default.

If a HTTP Basic Authentication request is sent with extremely long values for the username or password field, a buffer overflow will occur. Depending on the length of the string submitted, either the SERVER.NLM or the HTTPSTK.NLM process will halt with an ABEND error, resulting in a denial of service condition.

It may prove possible to execute arbitrary code as the server process. This has not, however, been confirmed.







 

Privacy Statement
Copyright 2009, SecurityFocus