Title : Novell ZENworks Authentication Protocol Multiple Vulnerabilities VUPEN ID : VUPEN/ADV-2005-0571 CVE ID : CVE-2005-1543 CWE ID : CWE-
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-05-18
Technical Description
Multiple vulnerabilities were identified in Novell ZENworks, which may be exploited by remote attackers to execute arbitrary commands. These flaws are due to several stack and heap overflow errors in the authentication protocol that does not properly validate user-supplied input, which may be exploited by an unauthenticated attacker to compromise a vulnerable system via specially crafted type 1 or type 2 requests.