Vulnerabilities > CVE-2006-4689 - Denial-Of-Service vulnerability in Microsoft Windows 2000, Windows 2003 Server and Windows XP
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
NONE Availability impact
PARTIAL Summary
Unspecified vulnerability in the driver for the Client Service for NetWare (CSNW) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 allows remote attackers to cause a denial of service (hang and reboot) via has unknown attack vectors, aka "NetWare Driver Denial of Service Vulnerability."
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 3 |
Nessus
NASL family | Windows : Microsoft Bulletins |
NASL id | SMB_NT_MS06-066.NASL |
description | The remote host contains a version of the Client Service for NetWare that is vulnerable to a buffer overflow. An attacker may exploit this to cause a denial of service by sending a malformed IPX packet to the remote host, or to execute arbitrary code by exploiting a flaw in the NetWare client. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 23643 |
published | 2006-11-14 |
reporter | This script is Copyright (C) 2006-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/23643 |
title | MS06-066: Vulnerability in the Client Service for NetWare Could Allow Remote Code Execution (923980) |
code |
|
Oval
accepted | 2007-02-20T13:40:30.055-05:00 | ||||||||||||||||
class | vulnerability | ||||||||||||||||
contributors |
| ||||||||||||||||
definition_extensions |
| ||||||||||||||||
description | Unspecified vulnerability in the driver for the Client Service for NetWare (CSNW) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 allows remote attackers to cause a denial of service (hang and reboot) via has unknown attack vectors, aka "NetWare Driver Denial of Service Vulnerability." | ||||||||||||||||
family | windows | ||||||||||||||||
id | oval:org.mitre.oval:def:413 | ||||||||||||||||
status | accepted | ||||||||||||||||
submitted | 2006-11-15T12:28:05 | ||||||||||||||||
title | Microsoft Client Service for NetWare Memory Corruption Vulnerability | ||||||||||||||||
version | 41 |
Saint
bid | 20984 |
description | Microsoft Client Service for NetWare tree name buffer overflow |
id | win_patch_netwaredrv |
osvdb | 30260 |
title | microsoft_netware_treename |
type | remote |
References
- http://secunia.com/advisories/22866
- http://securitytracker.com/id?1017224
- http://www.securityfocus.com/archive/1/451844/100/0/threaded
- http://www.securityfocus.com/bid/20984
- http://www.us-cert.gov/cas/techalerts/TA06-318A.html
- http://www.vupen.com/english/advisories/2006/4504
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-066
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A413