CVE-2008-2431
Last modified
CVE-2008-2431 is a vulnerability of currently unknown severity. Multiple buffer overflows in Novell iPrint Client before 5.06 allow remote attackers to execute arbitrary code by calling the Novell iPrint ActiveX control (aka ienipp.ocx) with (1) a long third argument to the GetDriverFile method; a long first argument to the (2) GetPrinterURLList or (3) GetPrinterURLList2 method; (4) a long argument to the GetFileList method; a long argument to the (5) GetServerVersion, (6) GetResourceList, or (7) DeleteResource method, related to nipplib.dll; a long uploadPath argument to the (8) UploadPrinterDriver or (9) UploadResource method, related to URIs; (10) a long seventh argument to the UploadResource method; a long string in the (11) second, (12) third, or (13) fourth argument to the GetDriverSettings method, related to the IppGetDriverSettings function in nipplib.dll; or (14) a long eighth argument to the UploadResourceToRMS method.. EPSS estimates a 46.33% chance of exploitation in the next 30 days.
Description
Multiple buffer overflows in Novell iPrint Client before 5.06 allow remote attackers to execute arbitrary code by calling the Novell iPrint ActiveX control (aka ienipp.ocx) with (1) a long third argument to the GetDriverFile method; a long first argument to the (2) GetPrinterURLList or (3) GetPrinterURLList2 method; (4) a long argument to the GetFileList method; a long argument to the (5) GetServerVersion, (6) GetResourceList, or (7) DeleteResource method, related to nipplib.dll; a long uploadPath argument to the (8) UploadPrinterDriver or (9) UploadResource method, related to URIs; (10) a long seventh argument to the UploadResource method; a long string in the (11) second, (12) third, or (13) fourth argument to the GetDriverSettings method, related to the IppGetDriverSettings function in nipplib.dll; or (14) a long eighth argument to the UploadResourceToRMS method.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Novell | Iprint | <= 5.04 |
| Novell | Iprint | 4.26 |
| Novell | Iprint | 4.27 |
| Novell | Iprint | 4.28 |
| Novell | Iprint | 4.30 |
| Novell | Iprint | 4.32 |
| Novell | Iprint | 4.34 |
| Novell | Iprint | 4.36 |
| Novell | Iprint | 4.38 |
References
- http://secunia.com/advisories/30667Vendor Advisory
- http://secunia.com/secunia_research/2008-27/advisory/Vendor Advisory
- http://secunia.com/advisories/30667Vendor Advisory
- http://secunia.com/secunia_research/2008-27/advisory/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-2431?
How severe is CVE-2008-2431?
How do I fix CVE-2008-2431?
Are you affected by CVE-2008-2431?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
