CVE-2011-2220: Buffer Overflow
Published Jul 14, 2011
·Updated
Stack-based buffer overflow in NFREngine.exe in Novell File Reporter Engine before 1.0.2.53, as used in Novell File Reporter and other products, allows remote attackers to execute arbitrary code via a crafted RECORD element.
Affected Software
2 affected components
Novell File Reporter Engine<=1.0.2.0
Novell File Reporter
Event History
Jul 14, 2011
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Data Sourced
11:55 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2011-2220?
CVE-2011-2220 has a critical severity rating due to its potential to allow remote code execution.
2
How do I fix CVE-2011-2220?
To fix CVE-2011-2220, upgrade to Novell File Reporter Engine version 1.0.2.53 or later.
3
What type of vulnerability is CVE-2011-2220?
CVE-2011-2220 is classified as a stack-based buffer overflow vulnerability.
4
Who is affected by CVE-2011-2220?
Users of Novell File Reporter Engine versions prior to 1.0.2.53 are affected by CVE-2011-2220.
5
Can CVE-2011-2220 be exploited remotely?
Yes, CVE-2011-2220 can be exploited remotely by sending a crafted RECORD element to the vulnerable software.