header-logo
Suggest Exploit
vendor:
Novell Netware
by:
Francis Provencher
7,5
CVSS
HIGH
Remote Code Execution
119
CWE
Product Name: Novell Netware
Affected Version From: Novell Netware 6.5 SP8
Affected Version To: Novell Netware 6.5 SP8
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Novell Netware 6.5 SP8
2012

Novell Netware XNFS caller_name xdrDecodeString Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Novell Netware. Authentication is not required to exploit this vulnerability. The specific flaw exists within the XDR decoding of the caller_name field. The XDR decoding routine does not properly validate the length of the field before copying it into a fixed-length buffer. An attacker can leverage this vulnerability to execute arbitrary code under the context of the application.

Mitigation:

Upgrade to the latest version of Novell Netware.
Source

Exploit-DB raw data: