vendor:
iPrint Client
by:
Trancer
7,6
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: iPrint Client
Affected Version From: 5.32
Affected Version To: 5.40
Patch Exists: YES
Related CWE: CVE-2010-3106
CPE: a:novell:iprint_client
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3, Windows Vista SP2
2010
Novell iPrint Client ActiveX Control ‘debug’ Buffer Overflow exploit for the Metasploit Framework
This module exploits a stack-based buffer overflow in Novell iPrint Client 5.40. When sending an overly long string to the 'debug' parameter in ExecuteRequest() property of ienipp.ocx an attacker may be able to execute arbitrary code.
Mitigation:
Update to the latest version of Novell iPrint Client