|
|
|
Vulnerability Note VU#653076Novell NetWare Client for Windows EnumPrinters() function vulnerable to buffer overflowOverviewA vulnerability exists in the Novell NetWare client that could allow a remote attacker to execute arbitrary code on an affected system.I. DescriptionNetWare is a network operating system produced and maintained by Novell. Novell provides NetWare clients for Microsoft Windows and Linux operating systems.From the Novell Client for Windows XP/2000 product overview:
There is a buffer overflow vulnerability in the EnumPrinters() function which is used in the nwspool.dll library. An attacker may be able to trigger the overflow by sending specially-crafted Remote Procedure Call (RPC) requests to the Spooler service on a vulnerable system. II. ImpactA remote unauthenticated attacker may be able to execute arbitrary code on a vulnerable system.III. SolutionUpgradeNovell has issued a beta upgrade that addresses this issue. See Novell Technical Information Document TID2974765 for more details.
References
The Zero Day Initiative disclosed this vulnerability. This document was written by Ryan Giobbi.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
||||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||