[NEWS] Novell iManager OpenSSL ASN Parsing Vulnerability
SecuriTeam <[email protected]>
| Newsgroups | gmane.comp.security.securiteam |
|---|---|
| Message-ID | <[email protected]> |
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com - - promotion The SecuriTeam alerts list - Free, Accurate, Independent. Get your security news from a reliable source. http://www.securiteam.com/mailinglist.html - - - - - - - - - Novell iManager OpenSSL ASN Parsing Vulnerability ------------------------------------------------------------------------ SUMMARY Novell <http://www.novell.com/products/consoles/imanager/> iManager is a Web-based administration console that provides customized access to network administration utilities. Novell iManager includes an installation of OpenSSL that is vulnerable to ASN.1 parsing bugs. DETAILS Vulnerable Systems: * Novell iManager version 2.0.2 OpenSSL ASN.1 Parsing vulnerability in Apache Multiple vulnerabilities were reported in the ASN.1 parsing code in OpenSSL. These issues could be exploited to cause a denial of service or to execute arbitrary code. The server in this case identifies itself as: Apache/2.0.48(Win32) mod_ssl/2.0.44 OpenSSL/0.9.7 mod_jk/1.2.4 When using the exploit downloaded from here: <http://www.securityfocus.com/data/vulnerabilities/exploits/ASN.1-Brute.c> http://www.securityfocus.com/data/vulnerabilities/exploits/ASN.1-Brute.c The server will stop responding, and an error will occurs. The Service is as default installed on port 8443 Patch Availability: These vulnerabilities are corrected in OpenSSL 0.9.7d. iManager 2.5 ships with OpenSSL 0.9.7d - to resolve the vulnerability upgrading is suggested. Disclosure Timeline: * 08.01.05 - Vulnerability discovered * 17.04.05 - Research ended * 18.04.05 - Novell Notified ([email protected]) * 18.04.05 - Received response from Ed Reed, Security Tzar, Novell, Inc. * 03.06.05 - Novell reports issue fixed * 13.06.05 - Public release ADDITIONAL INFORMATION The information has been provided by <mailto:[email protected]> Dennis Rand. The original article can be found at: <http://cirt.dk/advisories/cirt-32-advisory.pdf> http://cirt.dk/advisories/cirt-32-advisory.pdf ======================================== This bulletin is sent to members of the SecuriTeam mailing list. To unsubscribe from the list, send mail with an empty subject line and body to: [email protected] In order to subscribe to the mailing list, simply forward this email to: [email protected] ==================== ==================== DISCLAIMER: The information in this bulletin is provided "AS IS" without warranty of any kind. In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.