| Name | Novell.NetStorage.xsrvd.Long.Pathname.Code.Execution |
| Last Updated Date | Apr 27, 2010 |
| Release Date | Mar 16, 2010 |
| Severity | High |
| Impact | System Compromise: Remote attackers can gain control of vulnerable systems. |
| Description | This indicates an attack attempt against a code execution vulnerability in Novell Netstorage xsrvd. The vulnerability is caused by an error when the vulnerable software handles a malicious long URI. It allows a remote attacker to execute arbitrary code via sending a crafted HTTP request. |
| Affected Products | Novell NetStorage Novell NetWare 6.5 Support Pack 8 Novell Open Enterprise Server 2 (OES 2) Linux Support Pack 1 Novell Open Enterprise Server 2 (OES 2) Linux Support Pack 2 |
| Recommended Actions | Upgrade to latest version of the software. See http://www.novell.com/support/viewContent.do?externalId=7005282 for details |
| Reference/s | http://www.zerodayinitiative.com/advisories/ZDI-10-021/
|