VID |
28176 |
Severity |
20 |
Port |
139,445 |
Protocol |
TCP |
Class |
SMB |
Detailed Description |
The Novell Client software has a denial of service vulnerability in the 'srvloc.sys' file. Novell NetWare Client versions prior to 4.91 SP3 are vulnerable to a denial of service attack, caused by a vulnerability in the "srvloc.sys" component that does not properly handle malformed SLP packets sent to port 427. By sending a specially-crafted request to port 427, a remote attacker could cause a vulnerable application to crash.
* Note: This check requires an account with administrative privileges which can log into the host to scan. Absence of these condition will result in the check not being performed and a False Negative for all vulnerable hosts.
* References: https://secure-support.novell.com/KanisaPlatform/Publishing/859/3480790_f.SAL_Public.html http://www.frsirt.com/english/advisories/2006/4840 http://secunia.com/advisories/23244/
* Platforms Affected: Novell NetWare Client versions prior to 4.91 SP3 Microsoft Windows Any version |
Recommendation |
Upgrade to the latest version of Novell Client for Windows (4.91 SP3 or later), available from the Novell Downloads Web site at http://download.novell.com/index.jsp |
Related URL |
CVE-2006-6307 (CVE) |
Related URL |
21430 (SecurityFocus) |
Related URL |
30712 (ISS) |
|