Novell ZENworks Configuration Management is prone to a stack-based buffer-overflow vulnerability and an arbitrary file download vulnerability .
Credit:
The original article can be found at: http://www.securityfocus.com/bid/52659
The information has been provided by Luigi Auriemma .
Vulnerable Systems:
* Novell ZENworks Configuration Management 11.1A
* Novell ZENworks Configuration Management 11.1
Non-Vulnerable Systems:
* Novell ZENworks Configuration Management 11.2
Exploiting these issues may allow remote attackers to execute arbitrary code or retrieve arbitrary files within the context of the affected application
Vendor Status:
Novell as issued an update for this vulnerablity.
Patch Availability:
http://www.novell.com/support/kb/doc.php?id=7009901
CVE Information:
CVE-2011-3176
Disclosure Timeline:
Intial Release Mar 21 2012
Please enable JavaScript to view the comments powered by Disqus.
blog comments powered by