VRDA Feed by JPCERT/CC
  Vulnerability Response Decision Assistance Feed : Information for vulnerability impact analysis
[ about VRDA Feed | JPCERT/CC



 
Vulnerability Analysis Result (Revision No : 1) [ Download XML
VRDA-100107-001
Novell NetWare AFP Implementation Denial of Service Vulnerability
http://protekresearch.blogspot.com/2010/01/prl-cifsnlm-memory-consumption-denial.html

The CIFS and AFP protocols have a memory consumption problem when their received lot's of malformed arbitrary requests on their respective services. Sending arbitrary crafted requests to these services will consumme all the memory available,create multiples abends and finally crash the whole server.... It could take couple of minutes to hours (Depend of the memory available on the server ).




About This Analysis Information
Analysis Information Provider:
JPCERT/CC
First Published:
2010-01-07
Source Information Category:
Other (news, forums, etc.)
Last Updated:
2010-01-07




Affected Product Tags
cpe:/o:novell:netware     (Novell NetWare)
 


Vulnerability Analysis Results
[Information Source Reliability] [?]
X Low [?]

Medium [?]
High [?]

[Impact Level] [?]
Low [?]

X Low-Medium [?]
Medium-High [?]
High [?]

[Access Required] [?]
Physical [?]

Local [?]
X Non-routed [?]
Routed [?]

[Authentication] [?]
Privileged [?]

Standard [?]
Limited [?]
X None or Unnecessary [?]

[User Interaction Required] [?]
Complex [?]

Simple [?]
X None [?]

[Technical Difficulty] [?]
High [?]

Medium-High [?]
Low-Medium [?]
Low [?]

[Availability of Remediation] [?]
Official Patch [?]

Official Workaround [?]
X Unofficial Patch [?]
None [?]

[Incident Activity] [?]
None [?]

X Exploit or PoC [?]
Activity Observed [?]

Alternatives




References

Copyright © 2010 JPCERT/CC All Rights Reserved.