Vulnerability Name: | CVE-2011-4188 (CCN-74669) | ||||||||
Assigned: | 2011-10-25 | ||||||||
Published: | 2012-04-05 | ||||||||
Updated: | 2017-12-29 | ||||||||
Summary: | Buffer overflow in the Create Attribute function in jclient in Novell iManager 2.7.4 before patch 4 allows remote authenticated users to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted EnteredAttrName parameter, a related issue to CVE-2010-1929. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||||
CVSS v2 Severity: | 4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P) 3.0 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:N/A:P/E:U/RL:OF/RC:C)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-119 | ||||||||
Vulnerability Consequences: | Denial of Service | ||||||||
References: | Source: MITRE Type: CNA CVE-2011-4188 Source: CCN Type: SA48672 Novell iManager jclient "EnteredAttrName" Buffer Overflow Vulnerability Source: SECUNIA Type: UNKNOWN 48672 Source: CCN Type: Novell Document ID 7002971 iManager crashes due to buffer overflow in jclient Source: CONFIRM Type: Vendor Advisory http://www.novell.com/support/viewContent.do?externalId=7002971 Source: CCN Type: OSVDB ID: 81026 Novell iManager Web Interface jclient Create Attribute Function EnteredAttrName Parameter Parsing Remote Overflow Source: SECTRACK Type: UNKNOWN 1026894 Source: XF Type: UNKNOWN imanager-enteredattrname-dos(74669) Source: XF Type: UNKNOWN imanager-enteredattrname-dos(74669) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |