Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

APP:NOVELL:ZENWORKS-PREBOOT-SVC

Severity

High

Recommended

No

Recommended Action

Drop

Category

APP

Keywords

Novell ZENworks Configuration Management Preboot Service Buffer Overflow

Release Date

2010/10/25

Update Number

1798

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

APP: Novell ZENworks Configuration Management Preboot Service Buffer Overflow


This signature detects attempts to exploit a known buffer overflow vulnerability in Novell ZENworks Configuration Management. It is due to an input validation error in the Preboot Service when processing messages sent to port TCP/998. Remote attackers can exploit this to execute arbitrary code on the vulnerable system. In a successful code injection and execution attack, the behavior of the target machine is dependent on the intention of the malicious code. The code runs within the security context of the affected service, which is SYSTEM on Windows. In an unsuccessful attack, the affected service can terminate abnormally, leading to a denial-of-service condition.

Extended Description

Novell ZENworks Configuration Management is prone to an unspecified remote code-execution vulnerability. An attacker can leverage this issue to execute arbitrary code with SYSTEM-level privileges. Failed exploit attempts will result in a denial-of-service condition. Versions prior to ZENworks Configuration Management 10.3 are vulnerable.

Affected Products

  • Novell ZENworks Configuration Management 10.1
  • Novell ZENworks Configuration Management 10.1.2
  • Novell ZENworks Configuration Management 10.1.2 A

References

  • BugTraq: 39111
  • BugTraq: 40486
  • URL: http://www.novell.com/support/kb/doc.php?id=7005572

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out