Advisories Blog | G5 Cyber Security

Zero Day Initiative Advisory 10-138

Zero Day Initiative Advisory 10-138 – This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Novell iPrint Server. Authentication is not required to exploit this vulnerability. The flaw exists within the ‘/opt/novell/iprint/bin/ipsmd’ component this component communicates with ‘ilprsrvd’ which listens on TCP port 515. When handling an LPR opcode 0x01 packet type the process blindly copies user supplied data into a fixed-length buffer on the stack. A remote attacker can exploit this vulnerability to execute arbitrary code under the context of the iprint user.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/92479/ZDI-10-138.txt

Source: https://packetstormsecurity.com/files/92479/Zero-Day-Initiative-Advisory-10-138.html

Exit mobile version