First published: Thu Jul 14 2011(Updated: )
Stack-based buffer overflow in NFREngine.exe in Novell File Reporter Engine before 1.0.2.53, as used in Novell File Reporter and other products, allows remote attackers to execute arbitrary code via a crafted RECORD element.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Novell File Reporter | <=1.0.2.0 | |
Novell File Reporter |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-2220 has a critical severity rating due to its potential to allow remote code execution.
To fix CVE-2011-2220, upgrade to Novell File Reporter Engine version 1.0.2.53 or later.
CVE-2011-2220 is classified as a stack-based buffer overflow vulnerability.
Users of Novell File Reporter Engine versions prior to 1.0.2.53 are affected by CVE-2011-2220.
Yes, CVE-2011-2220 can be exploited remotely by sending a crafted RECORD element to the vulnerable software.