Stack-based Buffer Overflows in Novell Client Spooler Service
CVE-2007-2954

Currently unrated

Key Information:

Vendor
Novell
Status
Vendor
CVE Published:
31 August 2007

Summary

Multiple stack-based buffer overflows exist within the Spooler service (nwspool.dll) of Novell Client versions 4.91 SP2 through SP4 for Windows. These vulnerabilities can be exploited by remote attackers to execute arbitrary code by sending malformed long arguments in specific RPC requests, such as RpcAddPrinterDriver and RpcGetPrinterDriverDirectory, along with other undisclosed RPC requests. This creates significant risks for users if not addressed promptly.

References

EPSS Score

32% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.