[25399] in bugtraq
Re: cqure.net.20020408.netware_nwftpd.a
daemon@ATHENA.MIT.EDU (Brian Eckman)
Wed May 8 20:03:08 2002
Message-Id: <scd92e4a.014@sossgw.stu.umn.edu>
Date: Wed, 08 May 2002 13:54:43 -0500
From: "Brian Eckman" <ECKMA009@sossgw.stu.umn.edu>
To: <patrik.karlsson@se.pwcglobal.com>, <bugtraq@securityfocus.com>
Mime-Version: 1.0
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
> Problem: The Netware FTP server has a DOS vulnerability.
>
> Threat: An attacker could cause the server cpu to spike
> at 100% cpu hogging the server and causing a DOS,
> preventing legitimate users access to the server.
>
> Affected Software: Netware FTP server.
>
> Platform: Netware 6.0 SP 1 verified.
>
> Solution: Install patch from Novell as soon as it becomes
> available.
>
<snip>
This problem is fixed in nwftpd6.exe, dated April 26, 2002.
Reference:
http://support.novell.com/cgi-bin/search/searchtid.cgi?/2962252.htm
Download Update At:
http://support.novell.com/servlet/betafiledownload?file=/ftf/nwftpd6.exe/
Brian