CVE-2007-2954

Novell Client 4.91 SP2-SP4 - Remote Code Execution via Spooler Service RPC Requests

Title source: llm
STIX 2.1

Description

Multiple stack-based buffer overflows in the Spooler service (nwspool.dll) in Novell Client 4.91 SP2 through SP4 for Windows allow remote attackers to execute arbitrary code via certain long arguments to the (1) RpcAddPrinterDriver, (2) RpcGetPrinterDriverDirectory, and other unspecified RPC requests, aka Novell bug 300870, a different vulnerability than CVE-2006-5854.

References (9)

Core 9
Core References
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/3006
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/35824
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/25474
Patch, Vendor Advisory x_refsource_misc
http://secunia.com/secunia_research/2007-57/advisory/
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/26374
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/37321
Patch vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1018623
Third Party Advisory x_refsource_misc
http://www.zerodayinitiative.com/advisories/ZDI-07-045/

Scores

EPSS 0.2348
EPSS Percentile 96.0%

Details

CWE
CWE-119
Status published
Products (1)
novell/client 4.91 sp2 (3 CPE variants)
Published Aug 31, 2007
Tracked Since Feb 18, 2026