Release date:
Updated on:
Affected Systems:
Novell File Reporter 1.x
Description:
--------------------------------------------------------------------------------
Cve id: CVE-2011-0994
Novell File Reporter provides numerous File information stored on network servers such as existing File information, last Data Access time, File copy information, and File location, and supports storage space planning.
Novell File Reporter has a security vulnerability in implementation. Attackers can exploit this vulnerability to execute arbitrary code with system-level permissions and control the affected systems.
This vulnerability is caused by a boundary error in File Reporter Agent (NFRAgent.exe) when processing the content of some XML tags. stack buffer overflow can be caused by specially crafted data sent to TCP port 3037.
<* Source: Stephen Fewer
Link: http://www.zerodayinitiative.com/advisories/ZDI-11-116/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Novell
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://support.novell.com/security-alerts