PT-2013-4572 · Novell · Novell Client+1
Guest
·
Published
2013-07-31
·
Updated
2013-07-31
·
CVE-2013-3697
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Novell Client versions 4.91 SP5
Novell Client 2 versions SP2, SP3
Description
The issue is related to an integer overflow in kernel drivers, specifically NWFS.SYS and NCPL.SYS, which might allow local users to gain privileges. This can be achieved via a crafted 0x1439EB IOCTL call.
Recommendations
For Novell Client version 4.91 SP5, consider restricting access to the NWFS.SYS kernel driver until a patch is available.
For Novell Client 2 versions SP2 and SP3, consider disabling the NCPL.SYS kernel driver as a temporary workaround to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Novell Client
Novell Client 2