Integer Overflow in Novell Client's DPRPC Library Allows Remote Code Execution
CVE-2006-2304

Currently unrated

Key Information:

Vendor
Novell
Status
Vendor
CVE Published:
11 May 2006

Summary

The Novell Client experiences multiple integer overflow vulnerabilities within the DPRPC library (DPRPCW32.DLL). Attackers can exploit these vulnerabilities by sending specially crafted XDR encoded arrays, which contain fields specifying an excessively large number of elements. This can trigger integer overflow conditions in the ndps_xdr_array function and potentially execute arbitrary code on affected systems, compromising security and exposing sensitive information.

References

EPSS Score

13% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.