 |
Novell Client SRVLOC.SYS拒绝服务漏洞 |
|
|
| Novell Client SRVLOC.SYS拒绝服务漏洞 |
|
| 作者:佚名 文章来源:不详 点击数: 更新时间:2007-1-25 10:25:37 |
|
受影响系统:
Novell Client 4.91 SP2
Novell Client 4.91 SP1
Novell Client 4.91
不受影响系统:
Novell Client 4.91 SP3
描述: Novell Client是允许NetWare连接到Windows的工作站软件。
Novell Client在处理畸形请求报文时存在漏洞,远程攻击者可能利用此漏洞导致服务器拒绝服务。
如果向Novell Client的427端口发送了特制报文的话,就会导致srvloc.sys中出现以下拒绝服务情况:
IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at
an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: 00000006, memory referenced
Arg2: 00000002, IRQL
Arg3: 00000000, value 0 = read operation, 1 = write operation
Arg4: 804204bd, address which referenced memory
<*来源:Tyler Krpata
链接:http://secunia.com/advisories/23244/
https://secure-support.novell.com/KanisaPlatform/Publishing/859/3480790_f.SAL_Public.html
*>
建议:
厂商补丁:
Novell
目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载:
http://support.novell.com/security-alerts【转自世纪安全网 http://www.21safe.com】
|
|
| 文章录入:admin 责任编辑:admin |
|
|
上一篇文章: 关于Windows Internet服务器安全配置 下一篇文章: Linux Kernel get_fdb_entries溢出漏洞 |
|
|
| 【字体:小 大】【发表评论】【加入收藏】【告诉好友】【打印此文】【关闭窗口】 |
|
|
网友评论:(只显示最新10条。评论内容只代表网友观点,与本站立场无关!) |
|
|
|
|
|