|
|
| |
Credit:
The information has been provided by Francis Provencher .
The original article can be found at: http://www.zerodayinitiative.com/advisories/ZDI-11-087/
|
| |
Vulnerable Systems:
* Novell iPrint
Authentication is not required to exploit this vulnerability.
The flaw exists within the '/opt/novell/iprint/bin/ipsmd' component this component communicates with 'ilprsrvd' which listens on TCP port 515. When handling multiple LPR opcodes the process blindly copies user supplied data into a fixed-length buffer on the stack. A remote attacker can exploit this vulnerability to execute arbitrary code under the context of the iprint user.
Patch Availability:
The problem is documented in Novell TID 7007858:
http://download.novell.com/Download?buildid=KloKR_Cm
CVE Information:
CVE-2010-4328
Disclosure Timeline:
2010-12-01 - Vulnerability reported to vendor
2011-02-16 - Coordinated public release of advisory
|
|
|