Immune Systems:
* Novell ZENworks 7 Desktop Management Support Pack 1 Interim Release 4 Hot Patch 5
The flaw exists within the tftpd server component which listens by default on UDP port 69. When handling the filename in a Read Request (0x01) packet type the process blindly copies user supplied data into a fixed-length buffer on the stack. A remote attacker can exploit this vulnerability to execute arbitrary code under the context of the tftpd server process.