PT-2006-3292 · Novell · Ndps/Iprint Module+2
Published
2006-05-12
·
Updated
2018-10-18
·
CVE-2006-2327
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Novell NetWare versions 6.5 SP3 through 6.5 SP5
Description
The issue is related to multiple integer overflows in the DPRPC library, specifically in the NDPS/iPrint module of Novell Distributed Print Services. This occurs when an XDR encoded array with a field specifying a large number of elements is processed, triggering overflows in the
ndps xdr array function. This can allow remote attackers to execute arbitrary code.Recommendations
For Novell NetWare versions 6.5 SP3 through 6.5 SP5, consider restricting access to the vulnerable NDPS/iPrint module until a patch is available. As a temporary workaround, avoid using the
ndps xdr array function in the DPRPC library to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability. Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dprpc Library
Ndps/Iprint Module
Novell Netware