Novell iPrint Client ActiveX Control Multiple Stack Overflow Vulnerabilities
BID:29736
Info
Novell iPrint Client ActiveX Control Multiple Stack Overflow Vulnerabilities
| Bugtraq ID: | 29736 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-2908 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 12 2008 12:00AM |
| Updated: | Nov 04 2008 08:05PM |
| Credit: | Will Dormann |
| Vulnerable: |
Novell iPrint Client 'ienipp.ocx' ActiveX control 4.34 Novell iPrint Client 'ienipp.ocx' ActiveX control 4.32 Novell iPrint Client 'ienipp.ocx' ActiveX control 4.26 Novell iPrint Client 4.34 |
| Not Vulnerable: |
Novell iPrint Client 4.36 |
Discussion
Novell iPrint Client ActiveX Control Multiple Stack Overflow Vulnerabilities
Novell iPrint Client ActiveX control is prone to multiple stack-based buffer-overflow vulnerabilities.
An attacker can exploit these issues by tricking a victim into viewing a malicious web page. A successful attack will allow attacker-supplied code to run in the context of the currently logged-in user.
The issue affects versions prior to iPrint Client 4.36.
Novell iPrint Client ActiveX control is prone to multiple stack-based buffer-overflow vulnerabilities.
An attacker can exploit these issues by tricking a victim into viewing a malicious web page. A successful attack will allow attacker-supplied code to run in the context of the currently logged-in user.
The issue affects versions prior to iPrint Client 4.36.
Exploit / POC
Novell iPrint Client ActiveX Control Multiple Stack Overflow Vulnerabilities
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Novell iPrint Client ActiveX Control Multiple Stack Overflow Vulnerabilities
Solution:
The vendor has released patches. Please see the references for more information.
Solution:
The vendor has released patches. Please see the references for more information.
References
Novell iPrint Client ActiveX Control Multiple Stack Overflow Vulnerabilities
References:
References: