CVE-2009-1350: Input Validation
Published Apr 21, 2009
·Updated
Unspecified vulnerability in xtagent.exe in Novell NetIdentity Client before 1.2.4 allows remote attackers to execute arbitrary code by establishing an IPC$ connection to the XTIERRPCPIPE named pipe, and sending RPC messages that trigger a dereference of an arbitrary pointer.
Affected Software
1 affected component
Novell Netidentity Client1.2.3
Remediation
Patch Available
Patch Available
Patch Available
Event History
Apr 21, 2009
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-1350?
CVE-2009-1350 is considered a critical vulnerability due to its potential to allow remote code execution.
2
How do I fix CVE-2009-1350?
To mitigate CVE-2009-1350, upgrade to Novell NetIdentity Client version 1.2.4 or later.
3
What causes the CVE-2009-1350 vulnerability?
CVE-2009-1350 arises from improper handling of RPC messages, leading to dereferencing of arbitrary pointers.
4
Who is affected by CVE-2009-1350?
CVE-2009-1350 affects users of Novell NetIdentity Client versions prior to 1.2.4.
5
Can CVE-2009-1350 be exploited remotely?
Yes, CVE-2009-1350 can be exploited remotely by attackers establishing an IPC$ connection.