CVE-2010-4227
Novell Netware RPC XNFS xdrDecodeString Remote Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
4Exploited in Wild
-Decision
Descriptions
The xdrDecodeString function in XNFS.NLM in Novell Netware 6.5 before SP8 allows remote attackers to cause a denial of service (abend) or execute arbitrary code via a crafted, signed value in a NFS RPC request to port UDP 1234, leading to a stack-based buffer overflow.
La función xdrDecodeString en XNFS.NLM en Novell Netware v6.5 anterior a SP8 permite a atacantes remotos provocar una denegación de servicio o ejecutar código arbitrario a través de un valor firmado manipulado en una peticion RPC NFS para el puerto UDP 1234, dando lugar a un desbordamiento de búfer basado en pila.
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Novell Netware. Authentication is not required to exploit this vulnerability.
The flaw exists within the XNFS.NLM component which listens by default on UDP port 1234. When handling the an NFS RPC request the xdrDecodeString function uses a user supplied length value to null terminate a string. This value can be signed allowing the NULL byte to be written at an arbitrary address. A remote attacker can exploit this vulnerability to execute arbitrary code under the context of the system.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2010-11-10 CVE Reserved
- 2011-02-18 CVE Published
- 2011-02-24 First Exploit
- 2024-08-07 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (12)
URL | Tag | Source |
---|---|---|
http://securityreason.com/securityalert/8104 | Third Party Advisory | |
http://www.securityfocus.com/archive/1/516645/100/0/threaded | Mailing List | |
http://www.securitytracker.com/id?1025119 | Vdb Entry | |
http://www.zerodayinitiative.com/advisories/ZDI-11-090 | X_refsource_misc |
|
https://exchange.xforce.ibmcloud.com/vulnerabilities/65625 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/16234 | 2011-02-24 | |
http://www.exploit-db.com/exploits/16234 | 2024-08-07 | |
http://www.protekresearchlab.com/index.php?option=com_content&view=article&id=24&Itemid=24 | 2024-08-07 | |
http://www.securityfocus.com/bid/46535 | 2024-08-07 |
URL | Date | SRC |
---|---|---|
http://download.novell.com/Download?buildid=1z3z-OsVCiE~ | 2018-10-10 |
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/43431 | 2018-10-10 | |
http://www.vupen.com/english/advisories/2011/0497 | 2018-10-10 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Novell Search vendor "Novell" | Netware Search vendor "Novell" for product "Netware" | <= 6.5 Search vendor "Novell" for product "Netware" and version " <= 6.5" | sp7 |
Affected
| ||||||
Novell Search vendor "Novell" | Netware Search vendor "Novell" for product "Netware" | 6.5 Search vendor "Novell" for product "Netware" and version "6.5" | - |
Affected
| ||||||
Novell Search vendor "Novell" | Netware Search vendor "Novell" for product "Netware" | 6.5 Search vendor "Novell" for product "Netware" and version "6.5" | sp1 |
Affected
| ||||||
Novell Search vendor "Novell" | Netware Search vendor "Novell" for product "Netware" | 6.5 Search vendor "Novell" for product "Netware" and version "6.5" | sp2 |
Affected
| ||||||
Novell Search vendor "Novell" | Netware Search vendor "Novell" for product "Netware" | 6.5 Search vendor "Novell" for product "Netware" and version "6.5" | sp3 |
Affected
| ||||||
Novell Search vendor "Novell" | Netware Search vendor "Novell" for product "Netware" | 6.5 Search vendor "Novell" for product "Netware" and version "6.5" | sp4 |
Affected
| ||||||
Novell Search vendor "Novell" | Netware Search vendor "Novell" for product "Netware" | 6.5 Search vendor "Novell" for product "Netware" and version "6.5" | sp5 |
Affected
| ||||||
Novell Search vendor "Novell" | Netware Search vendor "Novell" for product "Netware" | 6.5 Search vendor "Novell" for product "Netware" and version "6.5" | sp6 |
Affected
|