Novell ZENworks Configuration Management TFTP Remote Heap Overflow Vulnerability
RISK: Medium Risk
TYPE: Servers - Other Servers
A vulnerability has been identified in Novell ZENworks Configuration Management (ZCM), which could be exploited by remote attackers to compromise a vulnerable system. This issue is caused by a heap overflow error in the "novell-tftp.exe" component when processing requests sent to port 69/UDP, which could be exploited by remote unauthenticated attackers to crash an affected component or execute arbitrary code.
Impact
- Remote Code Execution
System / Technologies affected
- Novell ZENworks Configuration Management (ZCM) versions 11.x
- Novell ZENworks Configuration Management (ZCM) versions 10.x
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Apply patch for Novell ZENworks Configuration Management 11 :
http://download.novell.com/Download?buildid=KN7WZylayYc~ - Apply patch for Novell ZENworks Configuration Management 10.3.2 :
http://download.novell.com/Download?buildid=EXTzSp-HKZ8~ - Apply patch for Novell ZENworks Configuration Management 10.3.1 :
http://download.novell.com/Download?buildid=YO_dVg28uzY~
For earlier versions of ZCM 10, upgrade to version 10.3.2 or 10.3.1 and apply patches.
Vulnerability Identifier
Source
Related Link
Share with