Novell Privileged User Manager Remote Library Injection Vulnerability
BID:35752
Info
Novell Privileged User Manager Remote Library Injection Vulnerability
| Bugtraq ID: | 35752 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 21 2009 12:00AM |
| Updated: | Aug 21 2009 03:54PM |
| Credit: | Stephen Fewer of Harmony Security |
| Vulnerable: |
Novell Novell Privileged User Manager 2.2 |
| Not Vulnerable: | |
Discussion
Novell Privileged User Manager Remote Library Injection Vulnerability
Novell Privileged User Manager is prone to a vulnerability that allows a remote attacker to inject a malicious library.
The attacker can exploit this issue to inject and execute arbitrary malicious code in the context of the vulnerable application. Successful exploits can compromise the application and possibly the computer; other attacks are also possible.
Novell Privileged User Manager 2.2.0 is vulnerable.
Novell Privileged User Manager is prone to a vulnerability that allows a remote attacker to inject a malicious library.
The attacker can exploit this issue to inject and execute arbitrary malicious code in the context of the vulnerable application. Successful exploits can compromise the application and possibly the computer; other attacks are also possible.
Novell Privileged User Manager 2.2.0 is vulnerable.
Exploit / POC
Novell Privileged User Manager Remote Library Injection Vulnerability
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Novell Privileged User Manager Remote Library Injection Vulnerability
Solution:
The vendor has released a patch. Please see the references for details.
Solution:
The vendor has released a patch. Please see the references for details.
References
Novell Privileged User Manager Remote Library Injection Vulnerability
References:
References:
- Novell Privileged User Manager Homepage (Novell)
- ZDI-09-046: Novell Privileged User Manager Remote DLL Injection Vulnerability (ZDI Disclosures
) - Novell Privileged User Manager Remote Library Injection Vulnerability (Novell)
- ZDI-09-046: Novell Privileged User Manager Remote DLL Injection Vulnerability (Zero Day Initiative)