Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

APP:NOVELL:REPORTER-VOL

Severity

High

Recommended

No

Recommended Action

Drop

Category

APP

Keywords

Novell File Reporter VOL Tag Heap Buffer Overflow

Release Date

2013/08/04

Update Number

2287

Supported Platforms

idp-4.0+, isg-3.4+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

APP: Novell File Reporter VOL Tag Heap Buffer Overflow


This signature detects a known vulnerability against Novell File Reporter. It is due to insufficient bounds checking when handling SRS requests with multiple VOL tags. The resulting unbounded input can overflow a fixed size heap buffer. An remote unauthenticated attacker could exploit these vulnerabilities by sending specially crafted requests to the server. Successful exploitation could result in a heap buffer overflow resulting in code execution with SYSTEM privileges.

Extended Description

Heap-based buffer overflow in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to execute arbitrary code via a large number of VOL elements in an SRS record.

Affected Products

  • novell file_reporter 1.0.2

References

  • CVE: CVE-2012-4956

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out