PT-2006-3269 · Novell · Novell Client+1
Publicado
2006-05-11
·
Atualizado
2018-10-18
·
CVE-2006-2304
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Novell Client versions 4.83 SP3, 4.90 SP2, 4.91 SP2
Description
The issue is caused by multiple integer overflows in the DPRPC library, specifically in the
ndps xdr array function. This occurs when an XDR encoded array with a field specifying a large number of elements is processed, allowing remote attackers to execute arbitrary code. Initially, this was reported as a buffer overflow by Novell, but it was later determined that the root cause is an integer overflow.Recommendations
For Novell Client version 4.83 SP3, update to a version that fixes the integer overflows in the DPRPC library.
For Novell Client version 4.90 SP2, update to a version that fixes the integer overflows in the DPRPC library.
For Novell Client version 4.91 SP2, update to a version that fixes the integer overflows in the DPRPC library.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Dprpc Library
Novell Client