First published: Mon Aug 23 2010(Updated: )
The ienipp.ocx ActiveX control in the browser plugin in Novell iPrint Client before 5.42 does not properly validate the debug parameter, which allows remote attackers to execute arbitrary code or cause a denial of service (stack memory corruption) via a parameter value with a crafted length, related to the ExecuteRequest method.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Novell Iprint | =5.20b | |
Novell Iprint | =5.30 | |
Novell Iprint | =4.34 | |
Novell Iprint | =4.38 | |
Novell Iprint | =4.27 | |
Novell Iprint | <=5.40 | |
Novell Iprint | =4.32 | |
Novell Iprint | =4.26 | |
Novell Iprint | =5.12 | |
Novell Iprint | =4.36 | |
Novell Iprint | =4.28 | |
Novell Iprint | =5.32 | |
Novell Iprint | =4.30 | |
Novell Iprint | =5.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-3106 has a high severity rating due to its potential to allow remote code execution or denial of service.
CVE-2010-3106 affects various versions of Novell iPrint including 4.26, 4.27, 4.28, 4.30, 4.32, 4.34, 4.36, 4.38, 5.04, 5.12, 5.20b, 5.30, 5.32, and 5.40.
To fix CVE-2010-3106, you should upgrade to Novell iPrint Client version 5.42 or later.
CVE-2010-3106 can be exploited to execute arbitrary code or cause stack memory corruption leading to denial of service.
There are no well-documented workarounds for CVE-2010-3106, so updating to a secure version is the recommended approach.