PT-2011-3690 · Novell · Novell File Reporter Engine

Publicado

2011-06-27

·

Atualizado

2018-10-09

·

CVE-2011-2220

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Novell File Reporter Engine versions prior to 1.0.2.53
Description The issue is related to a stack-based buffer overflow in NFREngine.exe, which can be exploited by remote attackers to execute arbitrary code. This is achieved by sending a crafted RECORD element.
Recommendations For versions prior to 1.0.2.53, update to version 1.0.2.53 or later to resolve the issue. As a temporary workaround, consider restricting access to the NFREngine.exe to minimize the risk of exploitation.

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-2220
ZDI-11-227

Produtos afetados

Novell File Reporter Engine