Logic Flaw in Novell iPrint Client's ActiveX Control Leads to File Deletion Vulnerability
CVE-2010-3107
Currently unrated
Summary
A logic flaw in the ActiveX control (ienipp.ocx) within the browser plugin of Novell iPrint Client prior to version 5.42 allows unauthorized remote attackers to exploit the CleanUploadFiles method in the nipplib.dll module. This flaw improperly restricts file deletions, leading to the potential for a denial of service through recursive file deletion, which can disrupt users' systems and access.
References
Timeline
Vulnerability published
Vulnerability Reserved