CVE-2007-2954: Buffer Overflow
Multiple stack-based buffer overflows in the Spooler service (nwspool.dll) in Novell Client 4.91 SP2 through SP4 for Windows allow remote attackers to execute arbitrary code via certain long arguments to the (1) RpcAddPrinterDriver, (2) RpcGetPrinterDriverDirectory, and other unspecified RPC requests, aka Novell bug 300870, a different vulnerability than CVE-2006-5854.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-2954?
CVE-2007-2954 is considered a critical vulnerability due to the potential for remote code execution.
What software versions are affected by CVE-2007-2954?
CVE-2007-2954 affects Novell Client versions 4.91 SP2 through SP4.
How do I fix CVE-2007-2954?
To mitigate CVE-2007-2954, users should upgrade to a patched version of Novell Client that addresses this vulnerability.
What type of vulnerabilities does CVE-2007-2954 involve?
CVE-2007-2954 involves multiple stack-based buffer overflows in the Spooler service of Novell Client.
Can CVE-2007-2954 be exploited remotely?
Yes, CVE-2007-2954 can be exploited remotely through certain malformed RPC requests.