---------------------------------------------------------------------- Proof-of-Concept (PoC) and Extended Analysis available for customers. Get a free trial, contact sales@secunia.com ---------------------------------------------------------------------- TITLE: NovaBACKUP Network / NovaNet Denial of Service Vulnerability SECUNIA ADVISORY ID: SA39541 VERIFY ADVISORY: http://secunia.com/advisories/39541/ DESCRIPTION: mu-b has discovered a vulnerability in NovaBACKUP Network and NovaNet, which can be exploited by malicious people to cause a DoS (Denial of Service). The vulnerability is caused due to a NULL pointer dereference error when processing certain packets, which can be exploited to crash the service by sending specially crafted packets. The vulnerability is confirmed in NovaNet 12.00 (build 44717) for Windows and NovaBACKUP Network version 13.0.00.54970 for Windows. SOLUTION: Restrict network access to trusted users only. PROVIDED AND/OR DISCOVERED BY: mu-b ORIGINAL ADVISORY: http://archives.neohapsis.com/archives/fulldisclosure/2010-04/0355.html ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help private users keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/advisories/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/advisories/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------