vendor:
Netware
by:
Francis Provencher
7,5
CVSS
HIGH
Remote code execution
119
CWE
Product Name: Netware
Affected Version From: Netware 6.5
Affected Version To: Netware 6.5
Patch Exists: NO
Related CWE: N/A
CPE: Novell
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Netware 6.5
2010
Novell Netware OpenSSH Remote Stack Overflow
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Novell Netware. Authentication is not required to exploit this vulnerability. The specific flaw exists within the OpenSSH service. The service fails to properly validate user-supplied data when handling certain requests. An attacker can leverage this vulnerability to execute arbitrary code under the context of the SYSTEM user.
Mitigation:
Novell responded with an advisory without nothing to fix the vulnerability.