Home Page | Skip to Navigation | Skip to Content | Skip to Search | Skip to Footer

Update Protection against Novell iPrint Client ienipp.ocx target-frame Stack Buffer Overflow

Subscribe

Check Point Reference: CPAI-2010-127
Date Published:
Severity:
Source: Security Advisory: SA37169
Industry Reference(s): CVE-2009-1568
Protection Provided by: IPS-1
  • IPS-1
  • IPS-1 NGX R65
Who is Vulnerable?
Novell iPrint Client prior to 5.32
Vulnerability Description
A buffer overflow vulnerability exists in Novell iPrint Client, an application that allows users to install and manage printers, or submit print jobs from a web browser. The vulnerability is due to a boundary error in the ActiveX control when parsing target-frame parameter values. A remote attacker can exploit this vulnerability by persuading a target user to open a malicious web page. Successful exploitation could result in remote code execution.
Update/Patch Available
Novell has released an advisory to address this vulnerability.
Vulnerability Details
The vulnerability exists in the Novell iPrint client within the ActiveX control, specifically when handling overly large target-frame parameter values passed in during the ActiveX control object instantiation.

Protection Overview
The protection will detect and block attempts to use the Novel iPrint Active X control in HTML documents.

To configure the defense, select your product from the list below and follow the related protection steps.

IPS-1 & IPS-1 NGX R65

How Can I Protect My Network?
1. In the IPS-1 Policy Manager, click on the Protection tab.
2. In the Protection tree, click Application Intelligence > Badfiles, and select the ActiveX Parser protection group.
3. Click Novell iPrint Client ienipp.ocx target-frame Stack Buffer Overflow (IPS-1 NGX R65 only).
4. In the configuration pane, under Settings, check Active.
5. Click on Install Policy.

How Do I Know if My Network is Under Attack?
Upon attack, the following entries will be logged:

Alert Name: Badfiles ActiveX class in HTML file Alert/Filter
Description: Novell iPrint Client ienipp.ocx target-frame Stack Buffer Overflow