Novell Client 'nwspool.dll' EnumPrinters RPC Request Buffer Overflow Vulnerability
BID:27741
Info
Novell Client 'nwspool.dll' EnumPrinters RPC Request Buffer Overflow Vulnerability
| Bugtraq ID: | 27741 |
| Class: | Design Error |
| CVE: |
CVE-2008-0639 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 11 2008 12:00AM |
| Updated: | Mar 13 2008 05:01PM |
| Credit: | Anonymous and Avosani Gabriele are credited with the discovery of this vulnerability. |
| Vulnerable: |
Novell Client 4.91 SP4 Novell Client 4.91 SP3 Novell Client 4.91 SP2 |
| Not Vulnerable: | |
Discussion
Novell Client 'nwspool.dll' EnumPrinters RPC Request Buffer Overflow Vulnerability
Novell Client is prone to a buffer-overflow vulnerability.
A remote attacker may exploit this issue to execute arbitrary code with SYSTEM-level privileges, facilitating the compromise of affected computers. Failed exploit attempts will likely crash the application, denying service to legitimate users.
NOTE: This issue may have been caused by an incomplete patch for the vulnerability documented in BID 25092 ('Novell Client NWSPOOL.DLL Unspecified Buffer Overflow Vulnerability').
Novell Client 4.91 SP2 through SP4 are vulnerable; other versions may also be affected.
Novell Client is prone to a buffer-overflow vulnerability.
A remote attacker may exploit this issue to execute arbitrary code with SYSTEM-level privileges, facilitating the compromise of affected computers. Failed exploit attempts will likely crash the application, denying service to legitimate users.
NOTE: This issue may have been caused by an incomplete patch for the vulnerability documented in BID 25092 ('Novell Client NWSPOOL.DLL Unspecified Buffer Overflow Vulnerability').
Novell Client 4.91 SP2 through SP4 are vulnerable; other versions may also be affected.
Exploit / POC
Novell Client 'nwspool.dll' EnumPrinters RPC Request Buffer Overflow Vulnerability
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Novell Client 'nwspool.dll' EnumPrinters RPC Request Buffer Overflow Vulnerability
Solution:
Novell has released a Field Test File (FTF) to address this issue. Please see the references for more information.
Novell Client 4.91 SP4
Novell Client 4.91 SP3
Novell Client 4.91 SP2
Solution:
Novell has released a Field Test File (FTF) to address this issue. Please see the references for more information.
Novell Client 4.91 SP4
-
Novell 491psp2_3_4_nwspool_2.zip
http://download.novell.com/Download?buildid=Ui5qNQgEmHE~
Novell Client 4.91 SP3
-
Novell 491psp2_3_4_nwspool_2.zip
http://download.novell.com/Download?buildid=Ui5qNQgEmHE~
Novell Client 4.91 SP2
-
Novell 491psp2_3_4_nwspool_2.zip
http://download.novell.com/Download?buildid=Ui5qNQgEmHE~
References
Novell Client 'nwspool.dll' EnumPrinters RPC Request Buffer Overflow Vulnerability
References:
References:
- 5008300 Novell Client 4.91 Post-SP2/3/4 NWSPOOL.DLL 2 (Novell)
- Novell Homepage (Novell)
- ZDI-08-005 Novell Client NWSPOOL.DLL EnumPrinters Stack Overflow Vulnerability (Zero Day Initiative)