Release date:
Updated on:
Affected Systems:
Novell Netware 6.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 51352
Novell Netware is a commercial network operating system.
Novell Netware has a remote code execution vulnerability in the implementation of the XNFS. NLM component. Attackers can exploit this vulnerability to execute arbitrary code and completely control the affected computers.
The xnfs. nlm component used to process nfs rpc requests has a vulnerability. This process listens on UDP port 32779. When the xdr-encoded caller_name in the NLM_TEST request is decoded, the process uses the length provided by the user as the stack buffer copy size. Remote attackers can exploit this vulnerability to execute arbitrary code.
<* Source: vendor
Link: http://www.zerodayinitiative.com/advisories/ZDI-12-011/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Novell
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://support.novell.com/security-alerts