Novell iManager Schema Create Class Stack Buffer Overflow Vulnerability
BID:40480
Info
Novell iManager Schema Create Class Stack Buffer Overflow Vulnerability
| Bugtraq ID: | 40480 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2010-1929 CVE-2011-4188 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 23 2010 12:00AM |
| Updated: | Apr 09 2012 06:20AM |
| Credit: | Francisco Falcon of Core Security Technologies |
| Vulnerable: |
Novell iManager 2.7.3 Novell iManager 2.7.2 Novell iManager 2.7.1 Novell iManager 2.5 Novell iManager 2.0.2 Novell iManager 2.0 Novell iManager 2.7.3 FTF2 Novell iManager 2.7.0 Novell iManager 2.6.0 |
| Not Vulnerable: |
Novell iManager 2.7.4 Novell iManager 2.7.3 FTF4 |
Discussion
Novell iManager Schema Create Class Stack Buffer Overflow Vulnerability
Novell iManager is prone to a stack-based buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
Attackers may exploit this issue to execute arbitrary code with SYSTEM-level privileges. Successful exploits will completely compromise affected computers. Failed exploit attempts will result in a denial-of-service condition.
Versions prior to Novell iManager 2.7.4 are vulnerable.
Novell iManager is prone to a stack-based buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
Attackers may exploit this issue to execute arbitrary code with SYSTEM-level privileges. Successful exploits will completely compromise affected computers. Failed exploit attempts will result in a denial-of-service condition.
Versions prior to Novell iManager 2.7.4 are vulnerable.
Exploit / POC
Novell iManager Schema Create Class Stack Buffer Overflow Vulnerability
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following proof of concept is available:
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following proof of concept is available:
Solution / Fix
Novell iManager Schema Create Class Stack Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Note: Core Security Technologies has stated that Novell will be releasing updated packages in August 2010. Please see the references for more information.
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Note: Core Security Technologies has stated that Novell will be releasing updated packages in August 2010. Please see the references for more information.
References
Novell iManager Schema Create Class Stack Buffer Overflow Vulnerability
References:
References:
- CORE-2010-0316: Novell iManager Multiple Vulnerabilities (Core Security Technologies)
- iManager Homepage (Novell)