|
|
|
![]() |
Vulnerability Note VU#432097Novell Bordermanager VPN Service denial-of-service vulnerabilityOverviewA vulnerability exists in the Novell Bordermanager VPN service that could allow a remote attacker to cause a denial of service.I. DescriptionThe Novell Bordermanager product includes Virtual Private Network (VPN) capabilities, including support for the standard Internet Key Exchange (IKE) protocol. A flaw exists in the way the VPN service handles certain malformed IKE packets. This flaw creates a remotely exploitable denial of service vulnerability that could cause an affected device to crash. The specific nature of the IKE packet malformation exploiting the vulnerability is unknown.II. ImpactA remote attacker with the ability to craft malformed IKE packets could cause an "abnormal ending" (abend) in the IKE.NLM module. This condition creates a denial of service on the server and causes clients previously connected to the server to hang.III. SolutionApply a patch from the vendorPatches are available to address this issue. Please see the Systems Affected section of this document for more information.
ReferencesThanks to the Novell product security team for reporting this vulnerability. This vulnerability was discovered using the Striker test suite from Rapid7. This document was written by Chad R Dougherty.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||