Overview
Novell File Reporter 1.0.2 contains multiple vulnerabilities including a heap overflow, arbitrary file retrieval, and arbitrary file upload.
Description
The Rapid7 advisory states: CVE-2012-4956 - Heap Overflow |
Impact
A remote unauthenticated attacker may be able to execute code, retrieve arbitrary files, and upload arbitrary files to the host. |
Solution
Apply an Update |
Restrict Access |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 9.3 | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Temporal | 7.7 | E:F/RL:OF/RC:C |
Environmental | 1.9 | CDP:ND/TD:L/CR:ND/IR:ND/AR:ND |
References
Acknowledgements
Thanks to Juan Vazquez for reporting this vulnerability.
This document was written by Jared Allar.
Other Information
CVE IDs: | CVE-2012-4956, CVE-2012-4957, CVE-2012-4958, CVE-2012-4959 |
Date Public: | 2012-11-16 |
Date First Published: | 2012-11-16 |
Date Last Updated: | 2014-07-30 19:25 UTC |
Document Revision: | 21 |