CVE-2006-2304: Buffer Overflow
Multiple integer overflows in the DPRPC library (DPRPCW32.DLL) in Novell Client 4.83 SP3, 4.90 SP2 and 4.91 SP2 allow remote attackers to execute arbitrary code via an XDR encoded array with a field that specifies a large number of elements, which triggers the overflows in the ndpsxdrarray function. NOTE: this was originally reported to be a buffer overflow by Novell, but the original cause is an integer overflow.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-2304?
CVE-2006-2304 has a high severity rating due to its potential for remote code execution.
How do I fix CVE-2006-2304?
To fix CVE-2006-2304, update your Novell Client to a non-vulnerable version.
Which versions of Novell Client are affected by CVE-2006-2304?
CVE-2006-2304 affects Novell Client versions 4.83 SP3, 4.90 SP2, and 4.91 SP2.
Can CVE-2006-2304 be exploited remotely?
Yes, CVE-2006-2304 can be exploited remotely through crafted XDR encoded arrays.
What is the primary impact of CVE-2006-2304?
The primary impact of CVE-2006-2304 is arbitrary code execution on the vulnerable system.