CVE-2010-3105

Novell iPrint < 5.44 - Remote Code Execution via Uninitialized Pointer in PluginGetDriverFile

Title source: llm
STIX 2.1

Description

The PluginGetDriverFile function in Novell iPrint Client before 5.44 interprets an uninitialized memory location as a pointer value, which allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/42576
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11817
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/40805

Scores

EPSS 0.0524
EPSS Percentile 90.1%

Details

CWE
CWE-119
Status published
Products (15)
novell/iprint 4.26
novell/iprint 4.27
novell/iprint 4.28
novell/iprint 4.30
novell/iprint 4.32
novell/iprint 4.34
novell/iprint 4.36
novell/iprint 4.38
novell/iprint 5.04
novell/iprint 5.12
... and 5 more
Published Aug 23, 2010
Tracked Since Feb 18, 2026