 |
Novell Client SRVLOC.SYS远程拒绝服务漏洞 |
|
|
| Novell Client SRVLOC.SYS远程拒绝服务漏洞 |
|
| 作者:佚名 文章来源:不详 点击数: 更新时间:2007-1-26 15:17:42 |
|
2006-12-8 21:29:05
发布日期:2006-12-04 更新日期:2006-12-08
受影响系统:Novell Client 4.91 SP2
Novell Client 4.91 SP1
Novell Client 4.91 不受影响系统:Novell Client 4.91 SP3 描述:
BUGTRAQ ID: 21430
Novell Client是允许NetWare连接到Windows的工作站软件。
Novell Client在处理畸形请求报文时存在漏洞,远程攻击者可能利用此漏洞导致服务器拒绝服务。
如果向Novell Client的427端口发送了特制报文的话,就会导致srvloc.sys中出现以下拒绝服务情况:
IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at
an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: 00000006, memory referenced
Arg2: 00000002, IRQL
Arg3: 00000000, value 0 = read operation, 1 = write operation
Arg4: 804204bd, address which referenced memory
<*来源:Tyler Krpata
链接:http://secunia.com/advisories/23244/
https://secure-support.novell.com/KanisaPlatform/Publishing/859/3480790_f.SAL_Public.html
*>
建议:
厂商补丁:
Novell
------
目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载:
http://support.novell.com/security-alerts
|
|
| 文章录入:admin 责任编辑:admin |
|
|
上一篇文章: Sophos Anti-Virus多个拒绝服务和内存破坏漏洞 下一篇文章: Intel网卡驱动本地权限提升漏洞 |
|
|
| 【字体:小 大】【发表评论】【加入收藏】【告诉好友】【打印此文】【关闭窗口】 |
|
|
网友评论:(只显示最新10条。评论内容只代表网友观点,与本站立场无关!) |
|
|
|
|
|