[25402] in bugtraq

home help back first fref pref prev next nref lref last post

cqure.net.20020412.netware_sdmr.a

daemon@ATHENA.MIT.EDU (Patrik Karlsson)
Thu May 9 01:46:53 2002

Message-ID: <002601c1f677$797ef8b0$0401a8c0@lab.se>
From: "Patrik Karlsson" <patrik.karlsson@se.pwcglobal.com>
To: <bugtraq@securityfocus.com>
Date: Wed, 8 May 2002 12:02:34 +0200
MIME-Version: 1.0
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Transfer-Encoding: 8bit

cqure.net Security Vulnerability Report
No: cqure.net.20020412.netware_sdmr.a
========================================

Vulnerability Summary
---------------------
Problem:           The IPX compatibility issue Posted to BugTraq on
                   July 11, 2000 by Dimuthu Parussalla applies to
                   Netware 6.0 SP 1 as well.

Threat:            An attacker could cause the SDMR.NLM to abend
                   and in some cases reboot the server. See bid
                   1467 for more information.

Affected Software: Novell Netware 6.0 SP 1.

Solution:          Taken from Bugtraq bid 1467.
                   "IPX-Compatibility should not be enabled on
                   production servers."


Solution
--------
Disable IPX-Compatibility on production servers.

Additional Information
----------------------
Novell was contacted 20020412.

This vulnerability was found and researched by
Patrik Karlsson & Jonas Ländin
patrik.karlsson@se.pwcglobal.com
jonas.landin@ixsecurity.com

This document is also available at: http://www.cqure.net/advisories/



home help back first fref pref prev next nref lref last post