CVE-2006-2327
Severity CVSS v4.0:
Pending analysis
Type:
CWE-189
Numeric Errors
Publication date:
12/05/2006
Last modified:
03/04/2025
Description
Multiple integer overflows in the DPRPC library (DPRPCNLM.NLM) NDPS/iPrint module in Novell Distributed Print Services in Novell NetWare 6.5 SP3, SP4, and SP5 allow remote attackers to execute arbitrary code via an XDR encoded array with a field that specifies a large number of elements, which triggers the overflows in the ndps_xdr_array function.
Impact
Base Score 2.0
6.40
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:novell:netware:6.5:*:*:*:*:*:*:* | ||
cpe:2.3:o:novell:netware:6.5:sp1:*:*:*:*:*:* | ||
cpe:2.3:o:novell:netware:6.5:sp1.1a:*:*:*:*:*:* | ||
cpe:2.3:o:novell:netware:6.5:sp1.1b:*:*:*:*:*:* | ||
cpe:2.3:o:novell:netware:6.5:sp2:*:*:*:*:*:* | ||
cpe:2.3:o:novell:netware:6.5:sp3:*:*:*:*:*:* | ||
cpe:2.3:o:novell:netware:6.5:sp4:*:*:*:*:*:* | ||
cpe:2.3:o:novell:netware:6.5:sp5:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-May/046048.html
- http://securitytracker.com/id?1016068=
- http://support.novell.com/cgi-bin/search/searchtid.cgi?%2F2973700_htm=
- http://www.hustlelabs.com/novell_ndps_advisory.pdf
- http://www.osvdb.org/25433
- http://www.securityfocus.com/archive/1/434017/100/0/threaded
- http://www.securityfocus.com/bid/17922
- http://www.vupen.com/english/advisories/2006/1740
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26314
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-May/046048.html
- http://securitytracker.com/id?1016068=
- http://support.novell.com/cgi-bin/search/searchtid.cgi?%2F2973700_htm=
- http://www.hustlelabs.com/novell_ndps_advisory.pdf
- http://www.osvdb.org/25433
- http://www.securityfocus.com/archive/1/434017/100/0/threaded
- http://www.securityfocus.com/bid/17922
- http://www.vupen.com/english/advisories/2006/1740
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26314