From: SecuriTeam <support@securiteam.com.>
To: [email protected]
Date: 15 Jun 2005 10:44:33 +0200
Subject: [NEWS] Novell iManager OpenSSL ASN Parsing Vulnerability
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Message-Id: <20050615081550.2E7075741@mail.tyumen.ru.>
X-Virus-Scanned: antivirus-gw at tyumen.ru
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
The SecuriTeam alerts list - Free, Accurate, Independent.
Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html
- - - - - - - - -
Novell iManager OpenSSL ASN Parsing Vulnerability
------------------------------------------------------------------------
SUMMARY
Novell <http://www.novell.com/products/consoles/imanager/> iManager is a
Web-based administration console that provides customized access to
network administration utilities.
Novell iManager includes an installation of OpenSSL that is vulnerable to
ASN.1 parsing bugs.
DETAILS
Vulnerable Systems:
* Novell iManager version 2.0.2
OpenSSL ASN.1 Parsing vulnerability in Apache
Multiple vulnerabilities were reported in the ASN.1 parsing code in
OpenSSL. These issues could be exploited to cause a denial of service or
to execute arbitrary code.
The server in this case identifies itself as: Apache/2.0.48(Win32)
mod_ssl/2.0.44 OpenSSL/0.9.7 mod_jk/1.2.4
When using the exploit downloaded from here:
<http://www.securityfocus.com/data/vulnerabilities/exploits/ASN.1-Brute.c>
http://www.securityfocus.com/data/vulnerabilities/exploits/ASN.1-Brute.c
The server will stop responding, and an error will occurs.
The Service is as default installed on port 8443
Patch Availability:
These vulnerabilities are corrected in OpenSSL 0.9.7d.
iManager 2.5 ships with OpenSSL 0.9.7d - to resolve the vulnerability
upgrading is suggested.
Disclosure Timeline:
* 08.01.05 - Vulnerability discovered
* 17.04.05 - Research ended
* 18.04.05 - Novell Notified ([email protected])
* 18.04.05 - Received response from Ed Reed, Security Tzar, Novell, Inc.
* 03.06.05 - Novell reports issue fixed
* 13.06.05 - Public release
ADDITIONAL INFORMATION
The information has been provided by <mailto:advisory@cirt.dk.> Dennis
Rand.
The original article can be found at:
<http://cirt.dk/advisories/cirt-32-advisory.pdf>
http://cirt.dk/advisories/cirt-32-advisory.pdf
This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: [email protected]
In order to subscribe to the mailing list, simply forward this email to: [email protected]
DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.