CERT-In Vulnerability Note
CIVN-2013-0222
Denial of Service Vulnerability in Novell Remote Manager
Original Issue Date:December 16, 2013
Severity Rating: HIGH
Component Affected
- Novell Open Enterprise Server 11 (OES 11) Linux Support Pack 1
- Novell Open Enterprise Server 11 (OES 11) Linux
- Novell Open Enterprise Server 2 (OES 2) Linux
Overview
A vulnerability has been reported in Novell Remote Manager which could be exploited by the remote attacker to cause denial of service conditions.
Description
This vulnerability exists in Novell Remote Manager due to improper closing of connections in HTTPSTK service after the TCP handshake which could be exploited by the remote attacker to cause the target service to crash by making connections to the TCP port 8009.
Successful exploitation may cause denial of service conditions.
Solution
Apply appropriate patches as mentioned in the vendor's advisory
http://www.novell.com/support/kb/doc.php?id=7014063
Vendor Information
Novell
http://www.novell.com/support/kb/doc.php?id=7014063
References
Security tracker
http://securitytracker.com/id/1029427
CVE Name
CVE-2013-3707
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|