PT-2010-4553 · Novell+1 · Novell Iprint Client+1
Publicado
2010-08-23
·
Atualizado
2017-09-19
·
CVE-2010-3107
CVSS v2.0
7.1
Alta
| Vetor | AV:N/AC:M/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Novell iPrint Client versions prior to 5.42
Description
The issue is related to a logic flaw in the CleanUploadFiles method within the nipplib.dll module of the Novell iPrint Client browser plugin. This flaw, associated with a certain ActiveX control in ienipp.ocx, does not properly restrict the set of files to be deleted. As a result, remote attackers can exploit this to cause a denial of service through recursive file deletion.
Recommendations
For versions prior to 5.42, update to version 5.42 or later to resolve the issue. As a temporary workaround, consider restricting access to the nipplib.dll module or disabling the ActiveX control in ienipp.ocx to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Activex
Novell Iprint Client