vendor:
Novell Client
by:
SecurityFocus
7.5
CVSS
HIGH
Denial of Service
399
CWE
Product Name: Novell Client
Affected Version From: 3
Affected Version To: 03.01
Patch Exists: Yes
Related CWE: N/A
CPE: Novell_Client_3.0/3.01
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2002
Novell Client 3.0/3.01 Denial of Service Vulnerability
Novell client versions 3.0 and 3.01 for Windows platforms are vulnerable to a remotely exploitable vulnerability which could cause a denial of service. The client opens a listening tcp socket on port 427, to which if a SYN is sent, results in the machine locking with a 'blue screen' error. The only solution from that point is to reset the affected computer.
Mitigation:
Disable port 427 on the affected system or upgrade to a version of Novell Client that is not vulnerable.