CVE-2011-3174: Buffer Overflow
Buffer overflow in the DoFindReplace function in the ISGrid.Grid2.1 ActiveX control in InstallShield/ISGrid2.dll in AdminStudio in Novell ZENworks Configuration Management (ZCM) 10.2, 10.3, and 11 SP1 allows remote attackers to execute arbitrary code via a long bstrReplaceText parameter.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-3174?
CVE-2011-3174 has a critical severity rating due to the potential for remote code execution.
How do I fix CVE-2011-3174?
To fix CVE-2011-3174, upgrade to a patched version of Novell ZENworks Configuration Management that addresses this vulnerability.
What versions of Novell ZENworks Configuration Management are affected by CVE-2011-3174?
CVE-2011-3174 affects Novell ZENworks Configuration Management versions 10.2, 10.3, and 11 SP1.
Can CVE-2011-3174 be exploited remotely?
Yes, CVE-2011-3174 can be exploited remotely through the execution of arbitrary code via a specially crafted input.
What is the nature of the vulnerability identified as CVE-2011-3174?
CVE-2011-3174 is a buffer overflow vulnerability in the DoFindReplace function of the ISGrid.ActiveX control.