Release date:
Updated on:
Affected Systems:
Novell Open Enterprise Server 2.0.3
Novell Open Enterprise Server 2.0.2
Description:
--------------------------------------------------------------------------------
Bugtraq id: 46309
Cve id: CVE-2010-4328
Novell Open Enterprise Server is a business platform for network, communication and collaboration services.
The Novell Open Enterprise Server has a remote buffer overflow vulnerability. Remote attackers can exploit this vulnerability to execute arbitrary code in affected applications, resulting in DOS.
This vulnerability is caused by the/opt/novell/iprint/bin/ipsmd component that communicates with the "ilprsrvd" listening on TCP port 515. When processing multiple LPR operation codes, the process blindly copies the data provided by the user to a fixed-length buffer on the stack.
<* Source: Francis Provencher
Link: http://marc.info /? L = bugtraq & m = 129796089510122 & w = 2
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Novell
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://support.novell.com/security-alerts