iDefense Security Advisory 12.01.06 – Remote exploitation of an integer overflow vulnerability in Novell Inc.’s ZENworks Asset Management could potentially allow an attacker to execute arbitrary code with the privileges of the administrator. A heap overflow may occur when processing specially crafted packets sent to the Task Server or Collection Server daemons. This problem specifically exists due to an integer overflow when allocating memory for remotely supplied data. iDefense has confirmed the existence of this vulnerability in version 7.0.0.36 of the CClient.exe and Msg.dll files included with Novell Inc’s ZENworks Asset Management 7.0 SP1. Older versions are suspected to be vulnerable as well.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/52742/12.01.06-2.txt
Source: https://packetstormsecurity.com/files/52742/iDEFENSE-Security-Advisory-2006-12-01.2.html

