Preemptive Protection against Novell Client Print Provider RPC Buffer Overflow Vulnerability
| Check Point Reference: | CPAI-2007-107 | |
| Date Published: | ||
| Severity: | ||
| Source: | Secunia Advisory: SA26238 | |
| Protection Provided by: |
VPN-1
|
|
| Who is Vulnerable? Novell Client for Windows 4.91 SP4 | ||
| Vulnerability Description A buffer overflow vulnerability has been discovered in Novell Client for Windows. The flaw is due to a boundary error in Novell Client's Spooler Service (nwspool.dll). The vulnerable service is included with the Novell Client for Microsoft Windows, and provides access to remote printing services via Remote Procedure Call (RPC). An attacker may exploit this vulnerability to execute arbitrary code on an affected system. |
||
|
Update/Patch Available Apply patch: Novell |
|
|
Vulnerability Details The vulnerability is due to an error in Novell Client's Spooler Service (nwspool.dll) that fails to properly handle long arguments passed in RPC requests. A remote attacker can exploit this issue by specially crafting a malicious RPC request and sending it to the Print Spooler RPC interface of an affected system. Successful exploitation may allow remote code execution. |
Protection Overview
Users are protected against this vulnerability if the Novell Print Spooler protection addressed in CPAI-2007-021 has been applied.
To configure the defense, select your product from the list below and follow the related protection steps.