Short Name |
APP:HPOV:CLASS-NAME-OF |
|---|---|
Severity |
Critical |
Recommended |
Yes |
Recommended Action |
Drop |
Category |
APP |
Keywords |
Novell iManager Class Name Remote Buffer Overflow |
Release Date |
2010/10/01 |
Update Number |
1784 |
Supported Platforms |
idp-4.0+, isg-3.1.134269+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+ |
This signature detects attempts to exploit a known buffer overflow vulnerability in Novell iManager. It is due to insufficient validation of the class name parameter when handling HTTP requests sent to the "/nps/servlet/webacc/" module. A remote authenticated attackers can exploit this on the target server by sending a crafted HTTP POST request. A successful attack can result in arbitrary code execution with SYSTEM privileges.
Novell iManager is prone to a stack-based buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data. Attackers may exploit this issue to execute arbitrary code with SYSTEM-level privileges. Successful exploits will completely compromise affected computers. Failed exploit attempts will result in a denial-of-service condition. Versions prior to Novell iManager 2.7.4 are vulnerable.