Stack-based Buffer Overflows in Novell Client Spooler Service
CVE-2007-2954
Currently unrated
Summary
Multiple stack-based buffer overflows exist within the Spooler service (nwspool.dll) of Novell Client versions 4.91 SP2 through SP4 for Windows. These vulnerabilities can be exploited by remote attackers to execute arbitrary code by sending malformed long arguments in specific RPC requests, such as RpcAddPrinterDriver and RpcGetPrinterDriverDirectory, along with other undisclosed RPC requests. This creates significant risks for users if not addressed promptly.
References
EPSS Score
32% chance of being exploited in the next 30 days.
Timeline
Vulnerability published
Vulnerability Reserved