CVE-2008-2908
Novell iPrint Client - ActiveX Control Buffer Overflow
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Multiple stack-based buffer overflows in a certain ActiveX control in ienipp.ocx in Novell iPrint Client for Windows before 4.36 allow remote attackers to execute arbitrary code via a long value of the (1) operation, (2) printer-url, or (3) target-frame parameter. NOTE: some of these details are obtained from third party information.
Múltiples desbordamientos de búfer basados en pila en un determinado control ActiveX de ienipp.ocx en Novell iPrint Client para Windows versiones anteriores a 4.36 permiten a atacantes remotos ejecutar código de su elección a través un valor largo de los parámetros (1) operation, (2) printer-url, o (3) target-frame.
NOTA: algunos de estos detalles han sido obtenidos a partir de la información de terceros.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2008-06-16 First Exploit
- 2008-06-30 CVE Reserved
- 2008-06-30 CVE Published
- 2024-08-07 CVE Updated
- 2024-09-19 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5028061.html | X_refsource_confirm | |
http://www.kb.cert.org/vuls/id/145313 | Third Party Advisory | |
http://www.securityfocus.com/bid/29736 | Vdb Entry | |
http://www.securitytracker.com/id?1020303 | Vdb Entry | |
http://www.vupen.com/english/advisories/2008/1837/references | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/43085 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/16508 | 2008-06-16 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/30709 | 2017-08-08 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Novell Search vendor "Novell" | Iprint Client Search vendor "Novell" for product "Iprint Client" | <= 4.35 Search vendor "Novell" for product "Iprint Client" and version " <= 4.35" | windows |
Affected
|