Novell NetWare Distributed Print Services Integer Overflow Vulnerability
BID:17922
CVE-2006-2327 |Info
Novell NetWare Distributed Print Services Integer Overflow Vulnerability
| Bugtraq ID: | 17922 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 09 2006 12:00AM |
| Updated: | May 16 2006 10:54PM |
| Credit: | Ryan Smith & Alex Wheeler discovered this issue. |
| Vulnerable: |
Novell Open Enterprise Server (OES) 0 Novell Netware 6.5 SP5 Novell Netware 6.5 SP4 Novell Netware 6.5 SP1.1(b) Novell Netware 6.5 SP1.1(a) Novell Netware 6.5 SP3 Novell Netware 6.5 SP2 Novell Netware 6.5 SP1 Novell Netware 6.5 Novell Client 4.91 SP2 Novell Client 4.91 SP1 Novell Client 4.91 Novell Client 4.90 SP2 Novell Client 4.83 SP3 |
| Not Vulnerable: | |
Discussion
Novell NetWare Distributed Print Services Integer Overflow Vulnerability
Novell NetWare Distributed Print Services is prone to an integer-overflow vulnerability.
An attacker could exploit this vulnerability to execute arbitrary code in the context of the vulnerable application. Failed exploit attempts will likely cause denial-of-service conditions. Since the vulnerable application executes with administrative privileges, this may facilitate the complete remote compromise of affected computers.
Novell NetWare Distributed Print Services is prone to an integer-overflow vulnerability.
An attacker could exploit this vulnerability to execute arbitrary code in the context of the vulnerable application. Failed exploit attempts will likely cause denial-of-service conditions. Since the vulnerable application executes with administrative privileges, this may facilitate the complete remote compromise of affected computers.
Exploit / POC
Novell NetWare Distributed Print Services Integer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution / Fix
Novell NetWare Distributed Print Services Integer Overflow Vulnerability
Solution:
Fixes are available; please see the referenced vendor advisories for further information.
Novell Client 4.91 SP2
Novell Netware 6.5 SP3
Novell Netware 6.5 SP5
Novell Netware 6.5 SP4
Solution:
Fixes are available; please see the referenced vendor advisories for further information.
Novell Client 4.91 SP2
-
Novell 491psp2_dprpcw32.exe
http://support.novell.com/servlet/filedownload/sec/ftf/491psp2_dprpcw3 2.exe
Novell Netware 6.5 SP3
-
Novell dprpc_security.exe
http://support.novell.com/servlet/filedownload/pub/dprpc_security.exe
Novell Netware 6.5 SP5
-
Novell dprpc_security.exe
http://support.novell.com/servlet/filedownload/pub/dprpc_security.exe
Novell Netware 6.5 SP4
-
Novell dprpc_security.exe
http://support.novell.com/servlet/filedownload/pub/dprpc_security.exe
References
Novell NetWare Distributed Print Services Integer Overflow Vulnerability
References:
References:
- NDPS client remote integer overflow vulnerability (Novell)
- NDPS on NetWare remote integer overflow vulnerability (Novell)
- TID2973700 - Security release for DPRPCNLM (Novell)
- TID2973719 - ovell Client 4.91 Post-SP2 DPRPCW32.DLL (Novell)
- Novell NDPS Remote Vulnerability (Server & Client) ("Ryan Smith"
)