CERT-In Vulnerability Note
CIVN-2003-0011
Novell iChain Exception Failure Denial of Service Vulnerability
Original Issue Date:October 28, 2003
Severity Rating: MEDIUM
Systems Affected
Novell iChain Server 2.2 SP1 Novell iChain Server 2.2 FP1a Novell iChain Server 2.2 FP1 Novell iChain Server 2.2
Overview
There is a vulnerability in Novell iChain service, this occurs due to the inability of iChain to handle a specific exceptional condition and arises because of a retrieve request by WGET on a directory that has no files. This vulnerability may cause a denial of service.
Impact
WGET causes an iChain abend. The abend occurs when WGET issues a RETR on a directory where no files exist.
Description
A key component of the Novell Nsure secure identity management solution, iChain controls access to application, web and network resources across all boundaries. As iChain is built upon Novell eDirectory, access control lists ACLs are used to provide a reliable security foundation. In addition to ACLs, iChain enhances network security by supporting several types of authentication methods, including smart card, username/password and token authentication.
A vulnerability has been identified in iChain, which can be exploited remotely by an attacker to cause DoS Denial of Service on a vulnerable system and potentially compromise it. The problem is due to the inability of iChain to handle a specific exceptional condition and arises because of a retrieve request by WGET on a directory that has no files.
Workaround
This vulnerability can be mitigated by creating a dummy file small text file in each of the following directories: sys:\etc\proxy\appliance\config\user\cert\backup\ sys:\etc\proxy\appliance\config\user\cert\temp\ sys:\etc\proxy\appliance\config\user\cert\ics\ sys:\etc\proxy\appliance\config\user\cert\sc\ sys:\etc\proxy\appliance\config\user\cert\tr\
Solution
Apply Patch Apply appropriate patch as given under iChain Server 2.2 SP1: iChain Server 2.2 FP1a: iChain Server 2.2 FP1: iChain Server 2.2:
Upgrade b2ic22sp2.exe http://support.novell.com/servlet/filedownload/sec /ftf/b2ic22sp2.exe Novell has released iChain Support Pack 2 Beta 2 to address this issue, refer TID2967231 for further information.
Vendor Information
Novell Novell Technical Information Document. - iChain - TID10086051
References
SecurityFocus Vulnerability Description
http://www.securityfocus.com/bid/8465
Novell Technical Information Document. - iChain - TID10086051
http://support.novell.com/cgi-bin/search/searchtid.cgi?/10086051.htm
iChain 2.2 Support Pack 2 beta Technical Information Document
http://support.novell.com/cgi-bin/search/searchtid.cgi?/2967231.htm
Novell iChain Home Page
http://www.novell.com/products/ichain/
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-2436857
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|