CVE-2010-4323: Buffer Overflow
Published Feb 18, 2011
·Updated
Heap-based buffer overflow in novell-tftp.exe in Novell ZENworks Configuration Manager (ZCM) 10.3.1, 10.3.2, and 11.0, and earlier versions, allows remote attackers to execute arbitrary code via a long TFTP request.
Affected Software
3 affected components
Novell ZENworks Configuration Manager<=11.0
Novell ZENworks Configuration Manager=10.3.1
Novell ZENworks Configuration Manager=10.3.2
Remediation
Patch Available
Event History
Feb 18, 2011
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-4323?
CVE-2010-4323 is classified as a high severity vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2010-4323?
To fix CVE-2010-4323, upgrade to Novell ZENworks Configuration Manager version 11.1 or later.
3
What software is affected by CVE-2010-4323?
CVE-2010-4323 affects Novell ZENworks Configuration Manager versions 10.3.1, 10.3.2, and 11.0 and earlier.
4
What type of vulnerability is CVE-2010-4323?
CVE-2010-4323 is a heap-based buffer overflow vulnerability.
5
Can CVE-2010-4323 be exploited remotely?
Yes, CVE-2010-4323 can be exploited remotely by attackers through a crafted TFTP request.