The OpenNET Project
 
Search (keywords):  SOFT ARTICLES TIPS & TRICKS SECURITY
LINKS NEWS MAN DOCUMENTATION


cqure.net.20020521.netware_nwftpd_fmtstr


<< Previous INDEX Search src Set bookmark Go to bookmark Next >>
Date: Tue, 25 Jun 2002 18:52:57 -0100 (GMT+1)
From: Patrik Karlsson <[email protected]>
To: [email protected]
Subject: cqure.net.20020521.netware_nwftpd_fmtstr


cqure.net Security Vulnerability Report
No: cqure.net.20020521.netware_nwftpd_fmtstr

Vulnerability Summary --------------------- Problem: The Netware FTP server has a DOS vulnerability. Threat: An attacker could cause the FTP server to ABEND resulting in a DOS where the whole server has to be restarted to regain full functionality. Affected Software: Novell Netware FTP server. Platforms: Netware 6.0 verified SP 1 + NWFTPD update. Solutions: Install patches from Novell as soon as they become available. Vulnerability Description ------------------------- The Netware FTP server has a formatstring condition which can be triggered by issuing format strings as login username. This will cause the server to ABEND. For the FTP server to regain full functionality a complete reboot has to be done. Additional Information ---------------------- Novell was contacted 20020521. This vulnerability was found by Patrik Karlsson & Jonas LДndin [email protected] [email protected] This document is also available at: http://www.cqure.net/advisories/

<< Previous INDEX Search src Set bookmark Go to bookmark Next >>



Партнёры:
PostgresPro
Inferno Solutions
Hosting by Hoster.ru
Хостинг:

Закладки на сайте
Проследить за страницей
Created 1996-2025 by Maxim Chirkov
Добавить, Поддержать, Вебмастеру