vendor:
Netware
by:
Francis Provencher
7,5
CVSS
HIGH
Remote Code Execution
119
CWE
Product Name: Netware
Affected Version From: Novell Netware 6.5 SP8
Affected Version To: Novell Netware 6.5 SP8
Patch Exists: Yes
Related CWE: N/A
CPE: Novell:NetWare:6.5:SP8
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Novell Netware 6.5 SP8
2012
Novell Netware XNFS.NLM NFS Rename Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Novell Netware. Authenication is not required to exploit this vulnerability. The specific flaw exists within the XNFS.NLM module. The issue lies in the handling of the NFSRENAME RPC call. By sending a specially crafted packet, an attacker can cause a stack-based buffer overflow.
Mitigation:
Update to the latest version of Novell Netware 6.5 SP8