This application requires Javascript for optimal performance.

Novell.Netware.XNFS.NLM.xdrDecodeString.Buffer.Overflow

Release Date

Dec 22, 2011

Severity

high

Impact

System Compromise: Remote attackers can gain control of vulnerable systems

Description

This indicates an attack attempt to exploit a Buffer Overflow vulnerability in Novell Netware.

The vulnerability is due to insufficient sanitizing of user supplied inputs in the xdrDecodeString function. As a result, a remote attacker can exploit this to execute arbitrary code within the context of the application or possibly cause a denial of service condition.

Affected Products

Novell Netware 6.5 SP8 and earlier versions

Recommended Actions

Apply patch available from the website.
http://download.novell.com/Download?buildid=Cfw1tDezgbw~

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2011-4191

Reference/s

http://www.securityfocus.com/bid/50804 (BugTraq)

Reference: VID-30575