|
Family: Gain root remotely --> Category: infos
SuSE Open Enterprise Server Novell Remote Manager HTTP Request Header Heap Overflow Vulnerability Vulnerability Scan
Vulnerability Scan Summary Checks for Novel Remort Manager HTTP Heap Overflow
Detailed Explanation for this Vulnerability Test
Synopsis :
Arbitrary code can be executed on the remote web server.
Description :
The remote host is running Novell Remote Manager HTTP service
for SuSE Enterprise or Open Enterprise Server.
The remote version of this software is vulnerable to a heap overflow
vulnerability which may be exploited by sending a negative value for
the 'Content-Length' field.
Since the 'httpstkd' service runs with the root rights, an
attacker can gain full control of the remote host.
Solution :
Novell has released a patch for the novell-nrm service :
http://www.novell.com/linux/security/advisories/2006_02_novellnrm.html
Threat Level:
High / CVSS Base Score : 7.0
(AV:R/AC:L/Au:NR/C:P/I:P/A:P/B:N)
Click HERE for more information and discussions on this network vulnerability scan.
|