Novell Client NWSPOOL.DLL Remote Buffer Overflow Vulnerability
BID:21220
Info
Novell Client NWSPOOL.DLL Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 21220 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-5854 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 21 2006 12:00AM |
| Updated: | Jan 29 2007 11:30PM |
| Credit: | An anonymous researcher discovered this issue. |
| Vulnerable: |
Novell Client 4.91 SP3 Novell Client 4.91 SP2 Novell Client 4.91 SP1 Novell Client 4.91 |
| Not Vulnerable: | |
Discussion
Novell Client NWSPOOL.DLL Remote Buffer Overflow Vulnerability
Novell Client is prone to a remote buffer-overflow vulnerability. Successful exploits may result in a denial-of-service condition or arbitrary code execution. Remote, anonymous attackers may exploit this issue via RPC requests.
This issue affects Novell Client 4.91; other versions may also be vulnerable.
Novell Client is prone to a remote buffer-overflow vulnerability. Successful exploits may result in a denial-of-service condition or arbitrary code execution. Remote, anonymous attackers may exploit this issue via RPC requests.
This issue affects Novell Client 4.91; other versions may also be vulnerable.
Exploit / POC
Novell Client NWSPOOL.DLL Remote Buffer Overflow Vulnerability
An exploit for members of the Immunity Partners program is available. This exploit is not known to be publicly available.
The following exploit code is available:
An exploit for members of the Immunity Partners program is available. This exploit is not known to be publicly available.
The following exploit code is available:
Solution / Fix
Novell Client NWSPOOL.DLL Remote Buffer Overflow Vulnerability
Solution:
Novell has released an advisory along with fixes to address this issue. Please see the references for more information.
Novell Client 4.91
Novell Client 4.91 SP3
Novell Client 4.91 SP1
Novell Client 4.91 SP2
Solution:
Novell has released an advisory along with fixes to address this issue. Please see the references for more information.
Novell Client 4.91
-
Novell 491psp3_nwspool.exe
http://support.novell.com/servlet/filedownload/sec/ftf/491psp3_nwspool .exe
Novell Client 4.91 SP3
-
Novell 491psp3_nwspool.exe
http://support.novell.com/servlet/filedownload/sec/ftf/491psp3_nwspool .exe
Novell Client 4.91 SP1
-
Novell 491psp3_nwspool.exe
http://support.novell.com/servlet/filedownload/sec/ftf/491psp3_nwspool .exe
Novell Client 4.91 SP2
-
Novell 491psp3_nwspool.exe
http://support.novell.com/servlet/filedownload/sec/ftf/491psp3_nwspool .exe
References
Novell Client NWSPOOL.DLL Remote Buffer Overflow Vulnerability
References:
References: