Novell Remote Manager Off-by-One Denial of Service Vulnerability


Description   Georgi Geshev has discovered a vulnerability in Novell Remote Manager, which can be exploited by malicious people to cause a DoS (Denial of Service)
The vulnerability is caused due to an off-by-one error in the "ProcessAuthorizationFailure()" function within the Small Http Interface Daemon (httpstkd) when processing certain HTTP headers for an error response. This can be exploited to cause the daemon to crash via e.g. an overly long string in a "Host" header.
The vulnerability is confirmed in version 2.0.2 Release 99.10. Other versions may also be affected.
     
Vulnerable Products   Vulnerable Software:
Novell Open Enterprise Server (OES) 11.xNovell Open Enterprise Server 2.xNovell Remote Manager 2.x
     
Solution   Apply updates.Novell Open Enterprise Server 2.0.3 Support Pack 3: http://download.novell.com/Download?buildid=9YXLaAwpygc~http://download.novell.com/Download?buildid=kciltAGwdSQ~Novell Open Enterprise Server 11: http://download.novell.com/Download?buildid=NSVJjHsKP5A~Novell Open Enterprise Server 11.1: http://download.novell.com/Download?buildid=GntTZUT5bLQ~
     
CVE  
     
References   https://bugzilla.novell.com/show_bug.cgi?id=778852
     
Vulnerability Manager Detection   No
     
IPS Protection  
ASQ Engine alarm Available Since
Possible buffer overflow in HTTP request/reply
3.2.0
     


 
 
 
 
 Risk level 
Low 

 Vulnerability First Public Report Date 
2012-08-02 

 Target Type 
Server 

 Possible exploit 
Remote