Title : Novell Client "NWSPOOL.DLL" Multiple Remote Buffer Overflow Vulnerabilities VUPEN ID : VUPEN/ADV-2007-3006 CVE ID : CVE-2007-2954 - CVE-2007-6701
Rated as : High Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-08-29
Technical Description
Multiple vulnerabilities have been identified in Novell Client, which could be exploited by remote attackers to cause a denial of service or take complete control of an affected system. These issues are caused by buffer overflow errors when processing specially crafted arguments passed to certain RPC requests (e.g. "RpcAddPrinterDriver" and "RpcGetPrinterDriverDirectory"), which could be exploited by remote attackers to crash an affected application or execute arbitrary code with elevated privileges.