|
|
|
|
| |
Credit:
The information has been provided by Secunia Research.
The original article can be found at: http://secunia.com/secunia_research/2008-33/
|
| |
Vulnerable Systems:
* Novell iPrint Client version 4.36
* Novell iPrint Client for Vista version 5.04
* Novell iPrint Client for Vista version 5.06
Immune Systems:
* Novell iPrint Client version 4.38
* Novell iPrint Client for Vista version 5.08
The vulnerability is caused due to a boundary error within the "IppCreateServerRef()" function in nipplib.dll. This can be exploited to cause a heap-based buffer overflow by passing an overly long, specially crafted string as argument to either "GetPrinterURLList()", "GetPrinterURLList2()", or "GetFileList2()" as provided by the Novell iPrint ActiveX control (ienipp.ocx).
Successful exploitation may allow execution of arbitrary code.
Time Table:
25/08/2008 - Vendor notified.
26/08/2008 - Vendor response.
03/09/2008 - Public disclosure.
CVE Information:
CVE-2008-2436
|
|
|
|
|