Novell Identity Manager Fan-Out Linux and UNIX Receiver Script Code Injection Vulnerability
BID:20016
CVE-2006-4803 |Info
Novell Identity Manager Fan-Out Linux and UNIX Receiver Script Code Injection Vulnerability
| Bugtraq ID: | 20016 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 14 2006 12:00AM |
| Updated: | Sep 14 2006 09:32PM |
| Credit: | This issue was disclosed by the vendor. |
| Vulnerable: |
Novell Identity Manager 3.0.1 |
| Not Vulnerable: | |
Discussion
Novell Identity Manager Fan-Out Linux and UNIX Receiver Script Code Injection Vulnerability
Novell Identity Manager is prone to a code-injection vulnerability.
A local attacker with administrative rights to the Identity Manager can exploit this issue to completely compromise an affected computer.
The vulnerability affects version 3.0.1; previous versions may be affected as well.
Novell Identity Manager is prone to a code-injection vulnerability.
A local attacker with administrative rights to the Identity Manager can exploit this issue to completely compromise an affected computer.
The vulnerability affects version 3.0.1; previous versions may be affected as well.
Exploit / POC
Novell Identity Manager Fan-Out Linux and UNIX Receiver Script Code Injection Vulnerability
To exploit this issue, an attacker can use the vulnerable application itself.
To exploit this issue, an attacker can use the vulnerable application itself.
Solution / Fix
Novell Identity Manager Fan-Out Linux and UNIX Receiver Script Code Injection Vulnerability
Solution:
The vendor has released a patch to address this issue.
Please see the references for more information.
Novell Identity Manager 3.0.1
Solution:
The vendor has released a patch to address this issue.
Please see the references for more information.
Novell Identity Manager 3.0.1
-
Novell idm301fansec1.tgz
http://support.novell.com/servlet/filedownload/sec/ftf/idm301fansec1.t gz
References
Novell Identity Manager Fan-Out Linux and UNIX Receiver Script Code Injection Vulnerability
References:
References: