Novell Open Enterprise Server HTTPSTK DoS Vulnerability
Release date:
Updated on:
Affected Systems:
Novell Open Enterprise Server 2.x
Novell Open Enterprise Server 11.x
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2013-3707
Novell Open Enterprise Server is a business platform for network, communication and collaboration services.
After a simple TCP handshake, Novell Open Enterprise Server does not properly close the connection related to the httpstk service. After successful exploitation, multiple CLOSE_WAIT connections can be established, then, the service will crash by sending a specially crafted TCP packet to port 8009.
<* Source: swappiness0
Link: http://secunia.com/advisories/55905/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Novell
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://support.novell.com/security-alerts
Http://www.novell.com/support/kb/doc.php? Id = 7014063