Lucene search

K
cve[email protected]CVE-2008-2436
HistorySep 05, 2008 - 4:08 p.m.

CVE-2008-2436

2008-09-0516:08:00
CWE-94
web.nvd.nist.gov
22
cve
buffer overflow
remote code execution
novell iprint
activex
nipplib.dll
security vulnerability

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.5

Confidence

Low

EPSS

0.226

Percentile

96.5%

Multiple heap-based buffer overflows in the IppCreateServerRef function in nipplib.dll in Novell iPrint Client 4.x before 4.38 and 5.x before 5.08 allow remote attackers to execute arbitrary code via a long argument to the (1) GetPrinterURLList, (2) GetPrinterURLList2, or (3) GetFileList2 function in the Novell iPrint ActiveX control in ienipp.ocx.

Affected configurations

NVD
Node
novelliprint_clientMatch4.26windows
OR
novelliprint_clientMatch4.32windows
OR
novelliprint_clientMatch4.35windows
OR
novelliprint_clientMatch4.36windows
OR
novelliprint_clientMatch5.06vista
VendorProductVersionCPE
novelliprint_client4.26cpe:/a:novell:iprint_client:4.26:::
novelliprint_client4.36cpe:/a:novell:iprint_client:4.36:::
novelliprint_client4.35cpe:/a:novell:iprint_client:4.35:::
novelliprint_client4.32cpe:/a:novell:iprint_client:4.32:::
novelliprint_client5.06cpe:/a:novell:iprint_client:5.06:::

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.5

Confidence

Low

EPSS

0.226

Percentile

96.5%