| |||||||||||||
| Test ID: | 1.3.6.1.4.1.25623.1.0.801645 |
| Category: | Buffer overflow |
| Title: | Novell ZENworks Handheld Management 'ZfHIPCND.exe' Buffer Overflow Vulnerability |
| Summary: | Check for the version of Novell ZENworks Handheld Management |
| Description: | Overview: This host is installed with Novell ZENworks Handheld Management and is prone to buffer overflow vulnerability. Vulnerability Insight: The flaw exists within module 'ZfHIPCND.exe', which allows remote attackers to execute arbitrary code via a crafted request to TCP port 2400. Impact: Successful exploitation could allow remote attackers to execute arbitrary code with SYSTEM privileges or cause denial of service. Impact Level: Application/System Affected Software/OS: Novell ZENworks Handheld Management 7 Fix: Apply the patch, available from below link, http://download.novell.com/Download?buildid=Sln2Lkqslmk~ ***** NOTE: Ignore this warning, if above mentioned patch is manually applied. ***** References: http://secunia.com/advisories/42130 http://www.securitytracker.com/id?1024691 http://www.zerodayinitiative.com/advisories/ZDI-10-230/ http://www.novell.com/support/viewContent.do?externalId=7007135 |
| Cross-Ref: |
BugTraq ID: 44700 Common Vulnerability Exposure (CVE) ID: CVE-2010-4299 http://www.zerodayinitiative.com/advisories/ZDI-10-230/ http://www.securitytracker.com/id?1024691 http://secunia.com/advisories/42130 |
| Copyright | Copyright (C) 2010 Greenbone Networks GmbH |
| This is only one of 32582 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |
|