Novell iPrint Client Multiple Vulnerabilities
Last Update Date:
8 Jun 2011 14:17
Release Date:
8 Jun 2011
6494
Views
RISK: High Risk
TYPE: Clients - Productivity Products
Multiple vulnerabilities have been identified in Novell iPrint Client, which could be exploited by remote attackers to compromise a vulnerable system.
- A boundary error in nipplib.dll when handling the "uri" parameter via "printer-url" can be exploited to cause a heap-based buffer overflow.
- A boundary error in nipplib.dll when handling the "profile-time" parameter via "printer-url" can be exploited to cause a heap-based buffer overflow.
- A boundary error in nipplib.dll when handling the "profile-name" parameter via "printer-url" can be exploited to cause a heap-based buffer overflow.
- A boundary error in nipplib.dll when handling the "file-date-time" parameter via "printer-url" can be exploited to cause a heap-based buffer overflow.
- A boundary error in nipplib.dll when handling the "driver-version" parameter via "printer-url" can be exploited to cause a heap-based buffer overflow.
- A boundary error in nipplib.dll when handling the "core-package" parameter via "printer-url" can be exploited to cause a heap-based buffer overflow.
- A boundary error in nipplib.dll when handling the "client-file-name" parameter via "printer-url" can be exploited to cause a heap-based buffer overflow.
- A boundary error in nipplib.dll when handling the "iprint-client-config-info" parameter via "printer-url" can be exploited to cause a stack-based buffer overflow.
- A boundary error in nipplib.dll when handling the "op-printer-list-all-jobs" parameter via "printer-url" can be exploited to cause a stack-based buffer overflow.
- A boundary error in nipplib.dll when handling a cookie associated with the "op-printer-list-all-jobs" parameter via "printer-url" can be exploited to cause a stack-based buffer overflow.
Impact
- Remote Code Execution
System / Technologies affected
- Novell iPrint Client 5.x
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Update to version 5.64.
Vulnerability Identifier
- CVE-2011-1699
- CVE-2011-1700
- CVE-2011-1701
- CVE-2011-1702
- CVE-2011-1703
- CVE-2011-1704
- CVE-2011-1705
- CVE-2011-1706
- CVE-2011-1707
- CVE-2011-1708
Source
Related Link
Share with