CERT-In Vulnerability Note
CIVN-2006-0114
Multiple Vulnerabilities in Client Service for NetWare
Original Issue Date:November 15, 2006
Severity Rating: LOW
Systems Affected
Microsoft Windows 2000 Service Pack 4 Microsoft Windows XP Service Pack 2 Microsoft Windows Server 2003 and Microsoft Windows Server 2003 Service Pack 1
Overview
Multiple vulnerabilities exist in Client Service for NetWare CSNW that could allow an attacker who successfully exploited one of these vulnerabilities to take complete control of the affected system.
Description
1. Memory Corruption Vulnerability in Client Service for NetWare
(
CVE-2006-4688
)
This is a remote code execution vulnerability caused by an unchecked buffer in Client Service for NetWare. An attacker who successfully exploited this vulnerability could remotely take complete control of an affected system with full user rights. NOTE: Windows XP Home Edition is not vulnerable to this issue. An attacker would need to be an authenticated user with valid logon credentials in order to successfully carry out an attack on Windows Server 2003 and Windows Server 2003 Service Pack 1.
2. Denial of Service Vulnerability in NetWare Driver
(
CVE-2006-4689
)
This is a Denial of Service Vulnerability caused by an unchecked buffer in the Client Service for NetWare. An attacker who exploited this vulnerability could cause the affected system to stop responding and automatically restart. NOTE: Windows XP Home Edition Service Pack 2 and Windows XP Media Center Edition 2005 are not vulnerable to this issue. An attacker would need to be an authenticated user with valid logon credentials in order to successfully carry out an attack on Windows Server 2003 and Windows Server 2003 Service Pack 1.
Workaround
- Remove the Client Service for NetWare if you do not need it.
- Block TCP ports 139 and 445 at the firewall
- Use a personal firewall
- Enable advanced TCP/IP filtering
- Block the affected ports by using IPSec
Solution
Apply appropriate updates as mentioned in the Microsoft Security Bulletin MS06-066
NOTE: This update replaces MS005-046 on Windows XP Service Pack 2 only.
Vendor Information
http://www.microsoft.com/technet/security/bulletin/ms06-066.mspx
References
Secunia
http://secunia.com/advisories/22866/
Security Focus
http://www.securityfocus.com/bid/20984/info
http://www.securityfocus.com/bid/21023/info
Security Tracker
http://www.securitytracker.com/alerts/2006/Nov/1017224.html
FrSirt
http://www.frsirt.com/english/advisories/2006/4504
CVE Name
CVE-2006-4688
CVE-2006-4689
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-2436857
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|