First published: Wed Nov 26 2008(Updated: )
Insecure method vulnerability in the GetFileList method in an unspecified ActiveX control in Novell iPrint Client before 5.06 allows remote attackers to list the image files in an arbitrary directory via a directory name in the argument.
Credit: PSIRT-CNA@flexerasoftware.com
Affected Software | Affected Version | How to fix |
---|---|---|
Novell Iprint | <=5.04 | |
Novell Iprint | =4.26 | |
Novell Iprint | =4.27 | |
Novell Iprint | =4.28 | |
Novell Iprint | =4.30 | |
Novell Iprint | =4.32 | |
Novell Iprint | =4.34 | |
Novell Iprint | =4.36 | |
Novell Iprint | =4.38 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-2432 is regarded as a high severity vulnerability due to its ability to allow unauthorized access to files on the server.
To fix CVE-2008-2432, upgrade to Novell iPrint Client version 5.06 or higher.
CVE-2008-2432 involves an insecure method vulnerability in the GetFileList method of an ActiveX control.
CVE-2008-2432 affects Novell iPrint Client versions prior to 5.06, including specific versions such as 4.26 through 4.38.
Remote attackers can exploit CVE-2008-2432 by passing a directory name to the vulnerable GetFileList method.