Описание
Heap-based buffer overflow in novell-tftp.exe in Novell ZENworks Configuration Manager (ZCM) 10.3.1, 10.3.2, and 11.0, and earlier versions, allows remote attackers to execute arbitrary code via a long TFTP request.
Ссылки
- Vendor Advisory
- Vendor Advisory
- Exploit
- PatchVendor Advisory
- Vendor Advisory
- Vendor Advisory
- Exploit
- PatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 11.0 (включая)
Одно из
cpe:2.3:a:novell:zenworks_configuration_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:novell:zenworks_configuration_manager:10.3.1:*:*:*:*:*:*:*
cpe:2.3:a:novell:zenworks_configuration_manager:10.3.2:*:*:*:*:*:*:*
EPSS
Процентиль: 97%
0.37156
Средний
7.5 High
CVSS2
Дефекты
CWE-119
Связанные уязвимости
github
больше 3 лет назад
Heap-based buffer overflow in novell-tftp.exe in Novell ZENworks Configuration Manager (ZCM) 10.3.1, 10.3.2, and 11.0, and earlier versions, allows remote attackers to execute arbitrary code via a long TFTP request.
EPSS
Процентиль: 97%
0.37156
Средний
7.5 High
CVSS2
Дефекты
CWE-119