Denial of Service Condition in Navision's Financials Server 2.50 and 2.60

A denial of service condition exists in the Navision Financial Server Versions 2.50 and 2.60 that allow a remote attacker to crash the server service.

Ken Pfeil

April 6, 2001

1 Min Read
ITPro Today logo in a gray background | ITPro Today

Reported April 3, 2001, by DefcomLabs.

 

VERSIONS AFFECTED

  • Navision Financials Server 2.50 for Windows 2000 and Windows NT

  • Navision Financials Server 2.60 for Windows 2000 and Windows NT

 

DESCRIPTION

ADenial of Service (DoS) condition exists in the Navision Financials Server versions2.50 and 2.60 for Windows 2000 and Windows NT that lets a remote attacker crash the server service. Bysending a null character followed by 30,000 bytes of the character "A" to TCP port2047, a buffer overflow occurs and results in the termination of the process server.exe.

 

VENDOR RESPONSE

 

Thevendor, Navision, recommends disallowingaccess to port 2047 from untrusted systems. Contact Navision-DamgaardSupport to obtain a patch for this issue.

 

CREDIT
Discovered by PeterGründl.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like