Vulnerable Systems:
* Novell iManager version 2.5.
The vulnerability specifically exists due to improper handling of a an HTTP POST request with a long TREE parameter. When such a request is received, a NULL pointer dereference occurs, leading to a crash of the service. iDefense Labs testing has indicated that any string longer than 256 bytes will be effective.
Exploitation requires that an attacker send a specially constructed HTTP request to the server. This crashes the server, making it unusable until it is restarted.
Vendor Status:
Novell has addressed this vulnerability within iManager version 2.6. Upgrading to this version will alleviate exposure to the vulnerability.