Novell iPrint Client CVE-2013-1091 Buffer Overflow Vulnerability
BID:59612
Info
Novell iPrint Client CVE-2013-1091 Buffer Overflow Vulnerability
| Bugtraq ID: | 59612 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2013-1091 |
| Remote: | Yes |
| Local: | No |
| Published: | May 02 2013 12:00AM |
| Updated: | Feb 13 2014 12:26AM |
| Credit: | Ivan Rodriguez Almuina |
| Vulnerable: |
Novell iPrint Client 5.78 Novell iPrint Client 5.77 Novell iPrint Client 5.76 Novell iPrint Client 5.75 Novell iPrint Client 5.74 Novell iPrint Client 5.73 Novell iPrint Client 5.72 Novell iPrint Client 5.64 Novell iPrint Client 5.56 Novell iPrint Client 5.52 Novell iPrint Client 5.44 Novell iPrint Client 5.32 Novell iPrint Client 5.30 Novell iPrint Client 5.08 Novell iPrint Client 5.06 Novell iPrint Client 5.04 Novell iPrint Client 4.38 Novell iPrint Client 4.36 Novell iPrint Client 4.34 |
| Not Vulnerable: | |
Discussion
Novell iPrint Client CVE-2013-1091 Buffer Overflow Vulnerability
Novell iPrint Client is prone to a buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
An attacker can exploit this issue to execute arbitrary code in the context of the application. Failed exploit attempts likely result in denial-of-service conditions.
Versions prior to Novell iPrint Client 5.90 are vulnerable.
Novell iPrint Client is prone to a buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
An attacker can exploit this issue to execute arbitrary code in the context of the application. Failed exploit attempts likely result in denial-of-service conditions.
Versions prior to Novell iPrint Client 5.90 are vulnerable.
Exploit / POC
Novell iPrint Client CVE-2013-1091 Buffer Overflow Vulnerability
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Novell iPrint Client CVE-2013-1091 Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Novell iPrint Client CVE-2013-1091 Buffer Overflow Vulnerability
References:
References:
- Novell Homepage (Novell)