| PROBLEM: | The Novell iPrint Client ActiveX control contains multiple stack buffer overflows, which can allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable system. |
| PLATFORM: | Novell iPrint |
| DAMAGE: | Execute arbitrary code. |
| SOLUTION: | Upgrade to the appropriate version. |
| VULNERABILITY ASSESSMENT: |
The risk is MEDIUM. By convincing a user to view a specially crafted HTMl document (e.g., a web page or an HTML email message or attachment), an attacker may be able to execute arbitrary code with the privileges of the user. |
| CVSS 2 BASE SCORE: TEMPORAL SCORE: VECTOR: |
6.4 5.3 (AV:N/AC:L/Au:N/C:P/I:P/A:N/E:F/RL:OF/RC:C) |
| LINKS: | |
| CIAC BULLETIN: | http://www.ciac.org/ciac/bulletins/s-321.shtml |
| ORIGINAL BULLETIN: | http://www.kb.cert.org/vuls/id/145313 |
| ADDITIONAL LINKS: | http://www.kb.cert.org/vuls/id/315107 http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5028061.html |
[***** Start US-CERT Vulnerability Note VU#145313 *****]
This issue is addressed in dne2000.sys version 3.21.12.17902. This driver is available from the DNE support page.
Cisco Windows VPN Client users should install version 5.0.03.0530, as specified in Cisco Support document CSCsm25860.
For other products that provide the DNE driver, please check with the vendor for updates.
| Vendor | Status | Date Updated |
|---|---|---|
| Blue Coat Systems | Vulnerable | 19-Jun-2008 |
| Cisco Systems, Inc. | Vulnerable | 18-Jun-2008 |
| Deterministic Networks, Inc | Vulnerable | 18-Jun-2008 |
| SafeNet | Vulnerable | 19-Jun-2008 |
http://www.digit-labs.org/files/exploits/dne2000-call.c
http://www.deterministicnetworks.com/support/dnesupport.asp
http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCsm25860
http://secunia.com/advisories/30728/
http://secunia.com/advisories/30753/
http://secunia.com/advisories/30744/
http://secunia.com/advisories/30747/
This vulnerability was reported by mu-b at Digit-Labs.
This document was written by Will Dormann.
| Date Public | 06/17/2008 |
| Date First Published | 06/18/2008 11:16:29 AM |
| Date Last Updated | 06/19/2008 |
| CERT Advisory | |
| CVE Name | |
| US-CERT Technical Alerts | |
| Metric | 22.50 |
| Document Revision | 6 |
[***** End US-CERT Vulnerability Note VU#145313 *****]
Voice: +1 925-422-8193 (7 x 24)
FAX: +1 925-423-8002
STU-III: +1 925-423-2604
E-mail: ciac@ciac.org
World Wide Web: http://www.ciac.org/
Anonymous FTP: ftp.ciac.org