// For flags

CVE-2008-2431

 

Severity Score

9.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Multiple buffer overflows in Novell iPrint Client before 5.06 allow remote attackers to execute arbitrary code by calling the Novell iPrint ActiveX control (aka ienipp.ocx) with (1) a long third argument to the GetDriverFile method; a long first argument to the (2) GetPrinterURLList or (3) GetPrinterURLList2 method; (4) a long argument to the GetFileList method; a long argument to the (5) GetServerVersion, (6) GetResourceList, or (7) DeleteResource method, related to nipplib.dll; a long uploadPath argument to the (8) UploadPrinterDriver or (9) UploadResource method, related to URIs; (10) a long seventh argument to the UploadResource method; a long string in the (11) second, (12) third, or (13) fourth argument to the GetDriverSettings method, related to the IppGetDriverSettings function in nipplib.dll; or (14) a long eighth argument to the UploadResourceToRMS method.

Múltiples desbordamientos de búfer en Novell iPrint Client anterior a v5.06; permiten a atacantes remotos ejecutar código de su elección al llamar al control ActiveX Novell iPrint (también conocido como ienipp.ocx) con (1) un tercer argumento largo al método GetDriverFile; un primer argumento largo a los métodos (2) GetPrinterURLList o (3) GetPrinterURLList2; (4) un argumento largo al método GetFileList; un argumento largo a los métodos (5) GetServerVersion, (6) GetResourceList o (7) DeleteResource relacionados con nipplib.dll; un argumento largo uploadPath a los métodos (8) UploadPrinterDriver o (9) UploadResource relacionados con URIs; (10) un séptimo argumento largo al método UploadResource; una cadena larga en los argumentos (11) segundo, (12) tercero o (13) cuarto al método GetDriverSettings relacionado con la función IppGetDriverSettings de nipplib.dll o (14) un octavo argumento largo al método UploadResourceToRMS.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2008-05-27 CVE Reserved
  • 2008-11-26 CVE Published
  • 2024-08-07 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Novell
Search vendor "Novell"
Iprint
Search vendor "Novell" for product "Iprint"
<= 5.04
Search vendor "Novell" for product "Iprint" and version " <= 5.04"
-
Affected
Novell
Search vendor "Novell"
Iprint
Search vendor "Novell" for product "Iprint"
4.26
Search vendor "Novell" for product "Iprint" and version "4.26"
-
Affected
Novell
Search vendor "Novell"
Iprint
Search vendor "Novell" for product "Iprint"
4.27
Search vendor "Novell" for product "Iprint" and version "4.27"
-
Affected
Novell
Search vendor "Novell"
Iprint
Search vendor "Novell" for product "Iprint"
4.28
Search vendor "Novell" for product "Iprint" and version "4.28"
-
Affected
Novell
Search vendor "Novell"
Iprint
Search vendor "Novell" for product "Iprint"
4.30
Search vendor "Novell" for product "Iprint" and version "4.30"
-
Affected
Novell
Search vendor "Novell"
Iprint
Search vendor "Novell" for product "Iprint"
4.32
Search vendor "Novell" for product "Iprint" and version "4.32"
-
Affected
Novell
Search vendor "Novell"
Iprint
Search vendor "Novell" for product "Iprint"
4.34
Search vendor "Novell" for product "Iprint" and version "4.34"
-
Affected
Novell
Search vendor "Novell"
Iprint
Search vendor "Novell" for product "Iprint"
4.36
Search vendor "Novell" for product "Iprint" and version "4.36"
-
Affected
Novell
Search vendor "Novell"
Iprint
Search vendor "Novell" for product "Iprint"
4.38
Search vendor "Novell" for product "Iprint" and version "4.38"
-
Affected