Lucene search

K
cve[email protected]CVE-2008-2431
HistoryNov 26, 2008 - 1:30 a.m.

CVE-2008-2431

2008-11-2601:30:00
CWE-119
web.nvd.nist.gov
32
novell
iprint
buffer overflow
remote code execution
activex
cve-2008-2431
security vulnerability

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.4

Confidence

Low

EPSS

0.471

Percentile

97.5%

Multiple buffer overflows in Novell iPrint Client before 5.06 allow remote attackers to execute arbitrary code by calling the Novell iPrint ActiveX control (aka ienipp.ocx) with (1) a long third argument to the GetDriverFile method; a long first argument to the (2) GetPrinterURLList or (3) GetPrinterURLList2 method; (4) a long argument to the GetFileList method; a long argument to the (5) GetServerVersion, (6) GetResourceList, or (7) DeleteResource method, related to nipplib.dll; a long uploadPath argument to the (8) UploadPrinterDriver or (9) UploadResource method, related to URIs; (10) a long seventh argument to the UploadResource method; a long string in the (11) second, (12) third, or (13) fourth argument to the GetDriverSettings method, related to the IppGetDriverSettings function in nipplib.dll; or (14) a long eighth argument to the UploadResourceToRMS method.

Affected configurations

NVD
Node
novelliprintRange≀5.04
OR
novelliprintMatch4.26
OR
novelliprintMatch4.27
OR
novelliprintMatch4.28
OR
novelliprintMatch4.30
OR
novelliprintMatch4.32
OR
novelliprintMatch4.34
OR
novelliprintMatch4.36
OR
novelliprintMatch4.38
VendorProductVersionCPE
novelliprint4.34cpe:/a:novell:iprint:4.34:::
novelliprint4.32cpe:/a:novell:iprint:4.32:::
novelliprint4.38cpe:/a:novell:iprint:4.38:::
novelliprintcpe:/a:novell:iprint::::
novelliprint4.26cpe:/a:novell:iprint:4.26:::
novelliprint4.36cpe:/a:novell:iprint:4.36:::
novelliprint4.30cpe:/a:novell:iprint:4.30:::
novelliprint4.27cpe:/a:novell:iprint:4.27:::
novelliprint4.28cpe:/a:novell:iprint:4.28:::

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.4

Confidence

Low

EPSS

0.471

Percentile

97.5%