Denial of Service Condition in Navision's Financials Server 2.50 and 2.60
A denial of service condition exists in the Navision Financial Server Versions 2.50 and 2.60 that allow a remote attacker to crash the server service.
April 6, 2001
Reported April 3, 2001, by DefcomLabs.
VERSIONS AFFECTED
Navision Financials Server 2.50 for Windows 2000 and Windows NT
Navision Financials Server 2.60 for Windows 2000 and Windows NT
DESCRIPTION
ADenial of Service (DoS) condition exists in the Navision Financials Server versions2.50 and 2.60 for Windows 2000 and Windows NT that lets a remote attacker crash the server service. Bysending a null character followed by 30,000 bytes of the character "A" to TCP port2047, a buffer overflow occurs and results in the termination of the process server.exe.
VENDOR RESPONSE
Thevendor, Navision, recommends disallowingaccess to port 2047 from untrusted systems. Contact Navision-DamgaardSupport to obtain a patch for this issue.
CREDIT
Discovered by PeterGründl.
About the Author
You May Also Like