[VulnWatch] cqure.net.20020412.netware_sdmr.a

From: Patrik Karlsson (patrik.karlsson@se.pwcglobal.com)
Date: Wed May 08 2002 - 06:09:27 EDT


cqure.net Security Vulnerability Report
No: cqure.net.20020412.netware_sdmr.a
========================================

Vulnerability Summary
---------------------
Problem: The IPX compatibility issue Posted to BugTraq on
                   July 11, 2000 by Dimuthu Parussalla applies to
                   Netware 6.0 SP 1 as well.

Threat: An attacker could cause the SDMR.NLM to abend
                   and in some cases reboot the server. See bid
                   1467 for more information.

Affected Software: Novell Netware 6.0 SP 1.

Solution: Taken from Bugtraq bid 1467.
                   "IPX-Compatibility should not be enabled on
                   production servers."

Solution
--------
Disable IPX-Compatibility on production servers.

Additional Information
----------------------
Novell was contacted 20020412.

This vulnerability was found and researched by
Patrik Karlsson & Jonas Ländin
patrik.karlsson@se.pwcglobal.com
jonas.landin@ixsecurity.com

This document is also available at: http://www.cqure.net/advisories/



This archive was generated by hypermail 2.1.7 : Wed Apr 09 2008 - 22:21:36 EDT