| Author: |
kkbass |
| Dated: |
Friday, October 02 2009 @ 11:52 AM CDT |
| Viewed: |
295 times |
|
SECUNIA ADVISORY ID:
SA36916
VERIFY ADVISORY:
http://secunia.com/advisories/36916/
DESCRIPTION:
A vulnerability has been reported in Novell NetWare, which can be
exploited by malicious people to compromise a vulnerable system.
The vulnerability is caused due to an error in the portmapper daemon
(PKERNEL.NLM) when handling RPC calls. This can be exploited to cause
a stack-based buffer overflow via a specially crafted CALLIT RPC
call.
Successful exploitation may allow execution of arbitrary code.
The vulnerability is reported in all 6.5 versions. Other versions may
also be affected.
SOLUTION:
Apply vendor patch:
http://download.novell.com/Download?buildid=DNxmXuyVPuY~
PROVIDED AND/OR DISCOVERED BY:
Nick DeBaggis, reported via ZDI
ORIGINAL ADVISORY:
Novell:
http://download.novell.com/Download?buildid=DNxmXuyVPuY~
ZDI:
http://www.zerodayinitiative.com/advisories/ZDI-09-067/
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.
Subscribe:
http://secunia.com/advisories/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/advisories/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.
----------------------------------------------------------------------
|
Trackback URL for this entry: http://www.abend.org/trackback.php/20091002115211396
No trackback comments for this entry.
|