Vulnerability Name: | CVE-2010-0317 (CCN-55389) | ||||||||
Assigned: | 2010-01-05 | ||||||||
Published: | 2010-01-05 | ||||||||
Updated: | 2018-10-10 | ||||||||
Summary: | Novell Netware 6.5 SP8 allows remote attackers to cause a denial of service (NULL pointer dereference, memory consumption, ABEND, and crash) via a large number of malformed or AFP requests that are not properly handled by (1) the CIFS functionality in CIFS.nlm Semantic Agent (Build 163 MP) 3.27 or (2) the AFP functionality in AFPTCP.nlm Build 163 SP 3.27. Note: some of these details are obtained from third party information. | ||||||||
CVSS v3 Severity: | 7.5 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
| ||||||||
CVSS v2 Severity: | 7.8 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C) 7.0 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C/E:F/RL:U/RC:UR)
7.0 High (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C/E:F/RL:U/RC:UR)
| ||||||||
Vulnerability Type: | CWE-399 | ||||||||
Vulnerability Consequences: | Denial of Service | ||||||||
References: | Source: MITRE Type: CNA CVE-2010-0317 Source: CCN Type: Protek Research Web site {PRL} CIFS.nlm Memory consumption Denial of Service Source: MISC Type: UNKNOWN http://protekresearch.blogspot.com/2010/01/prl-cifsnlm-memory-consumption-denial.html Source: CCN Type: SA38114 Novell NetWare AFP Implementation Denial of Service Vulnerability Source: SECUNIA Type: Vendor Advisory 38114 Source: CCN Type: SECTRACK ID: 1023400 NetWare CIFS and AFP Protocol Processing Flaws Let Remote Users Deny Service Source: EXPLOIT-DB Type: Exploit 11009 Source: CCN Type: Novell Web site NOVELL: Worldwide Source: CCN Type: OSVDB ID: 61604 Novell NetWare AFPTCP.nlm Module NULL Dereference Remote DoS Source: CCN Type: OSVDB ID: 61763 Novell NetWare CIFS.nlm Semantic Agent AFP Request NULL Dereference Remote DoS Source: BUGTRAQ Type: UNKNOWN 20100105 {PRL} Novell Netware CIFS And AFP Remote Memory Consumption DoS Source: BID Type: Exploit 37616 Source: CCN Type: BID-37616 Novell NetWare CIFS and AFP Handling Remote Denial of Service Vulnerabilities Source: SECTRACK Type: UNKNOWN 1023400 Source: VUPEN Type: Vendor Advisory ADV-2010-0041 Source: XF Type: UNKNOWN netware-afptcp-dos(55389) Source: XF Type: UNKNOWN netware-afptcp-dos(55389) Source: EXPLOIT-DB Type: EXPLOIT Offensive Security Exploit Database [01-05-2010] | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |