CVE-2010-4227

Severity CVSS v4.0:
Pending analysis
Type:
CWE-119 Buffer Errors
Publication date:
25/02/2011
Last modified:
11/04/2025

Description

The xdrDecodeString function in XNFS.NLM in Novell Netware 6.5 before SP8 allows remote attackers to cause a denial of service (abend) or execute arbitrary code via a crafted, signed value in a NFS RPC request to port UDP 1234, leading to a stack-based buffer overflow.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:novell:netware:*:sp7:*:*:*:*:*:* 6.5 (including)
cpe:2.3:a:novell:netware:6.5:*:*:*:*:*:*:*
cpe:2.3:a:novell:netware:6.5:sp1:*:*:*:*:*:*
cpe:2.3:a:novell:netware:6.5:sp2:*:*:*:*:*:*
cpe:2.3:a:novell:netware:6.5:sp3:*:*:*:*:*:*
cpe:2.3:a:novell:netware:6.5:sp4:*:*:*:*:*:*
cpe:2.3:a:novell:netware:6.5:sp5:*:*:*:*:*:*
cpe:2.3:a:novell:netware:6.5:sp6:*:*:*:*:*:*