PT-2010-4553 · Novell+1 · Novell Iprint Client+1

Publicado

2010-08-23

·

Atualizado

2017-09-19

·

CVE-2010-3107

CVSS v2.0

7.1

Alta

VetorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Novell iPrint Client versions prior to 5.42
Description The issue is related to a logic flaw in the CleanUploadFiles method within the nipplib.dll module of the Novell iPrint Client browser plugin. This flaw, associated with a certain ActiveX control in ienipp.ocx, does not properly restrict the set of files to be deleted. As a result, remote attackers can exploit this to cause a denial of service through recursive file deletion.
Recommendations For versions prior to 5.42, update to version 5.42 or later to resolve the issue. As a temporary workaround, consider restricting access to the nipplib.dll module or disabling the ActiveX control in ienipp.ocx to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-3107

Produtos afetados

Activex
Novell Iprint Client