Integer Overflow in Novell Client's DPRPC Library Allows Remote Code Execution
CVE-2006-2304
Currently unrated
Summary
The Novell Client experiences multiple integer overflow vulnerabilities within the DPRPC library (DPRPCW32.DLL). Attackers can exploit these vulnerabilities by sending specially crafted XDR encoded arrays, which contain fields specifying an excessively large number of elements. This can trigger integer overflow conditions in the ndps_xdr_array function and potentially execute arbitrary code on affected systems, compromising security and exposing sensitive information.
References
EPSS Score
13% chance of being exploited in the next 30 days.
Timeline
Vulnerability published
Vulnerability Reserved