PT-2011-5215 · Novell+1 · Novell-Novfsd+2

Publicado

1970-01-01

·

Atualizado

2012-01-02

·

CVE-2011-1710

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions novell-xtier-base versions 3.1.8 novell-novfsd (affected versions not specified)
Description The issue affects the Novell XTier framework and novell-novfsd package in SUSE Linux Enterprise, potentially leading to disruption of confidentiality, integrity, and availability of protected information. Exploitation can be done remotely. Specifically, multiple integer overflows in the HTTP server of the Novell XTier framework allow remote attackers to cause a denial of service or possibly execute arbitrary code via crafted header length variables, such as header length variables.
Recommendations For novell-xtier-base version 3.1.8, consider updating to a version that fixes the integer overflows in the HTTP server. For novell-novfsd, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-04427
BDU:2015-04428
CVE-2011-1710

Produtos afetados

Suse Linux Enterprise
Novell-Novfsd
Novell-Xtier-Base