CVE-2011-1699
UnknownEPSS 4.88%
Last modified
CVE-2011-1699 is a vulnerability of currently unknown severity. Heap-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.64 allows remote attackers to execute arbitrary code via a crafted uri parameter in a printer-url.. EPSS estimates a 4.88% chance of exploitation in the next 30 days.
Description
Heap-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.64 allows remote attackers to execute arbitrary code via a crafted uri parameter in a printer-url.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Novell | Iprint | <= 5.60 |
| Novell | Iprint | 4.26 |
| Novell | Iprint | 4.27 |
| Novell | Iprint | 4.28 |
| Novell | Iprint | 4.30 |
| Novell | Iprint | 4.32 |
| Novell | Iprint | 4.34 |
| Novell | Iprint | 4.36 |
| Novell | Iprint | 4.38 |
| Novell | Iprint | 5.04 |
| Novell | Iprint | 5.12 |
| Novell | Iprint | 5.20b |
| Novell | Iprint | 5.30 |
| Novell | Iprint | 5.32 |
| Novell | Iprint | 5.40 |
| Novell | Iprint | 5.42 |
| Novell | Iprint | 5.44 |
| Novell | Iprint | 5.50 |
| Novell | Iprint | 5.52 |
| Novell | Iprint | 5.56 |
References
- http://www.novell.com/support/php/search.do?cmd=displayKC&docType=kc&externalId=7008720Patch, Vendor Advisory
- http://www.novell.com/support/php/search.do?cmd=displayKC&docType=kc&externalId=7008720Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2011-1699?
Heap-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.64 allows remote attackers to execute arbitrary code via a crafted uri parameter in a printer-url.
How severe is CVE-2011-1699?
Severity scoring for CVE-2011-1699 is pending analysis. The EPSS model estimates a 4.88% probability of exploitation in the next 30 days.
How do I fix CVE-2011-1699?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
Are you affected by CVE-2011-1699?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
