CVE-2010-4227
Published Feb 25, 2011
Last updated 6 years ago
Overview
- Description
- The xdrDecodeString function in XNFS.NLM in Novell Netware 6.5 before SP8 allows remote attackers to cause a denial of service (abend) or execute arbitrary code via a crafted, signed value in a NFS RPC request to port UDP 1234, leading to a stack-based buffer overflow.
- Source
- cve@mitre.org
- NVD status
- Modified
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 10
- Impact score
- 10
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:C/I:C/A:C
Weaknesses
- nvd@nist.gov
- CWE-119
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:novell:netware:*:sp7:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EC47D609-E43E-4C31-ABC7-9CD84B65F57C", "versionEndIncluding": "6.5" }, { "criteria": "cpe:2.3:a:novell:netware:6.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D25AA90C-0008-4BEB-BCDE-0F1C3053E027" }, { "criteria": "cpe:2.3:a:novell:netware:6.5:sp1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FDF738B4-6AD7-4815-8617-38512659C4F4" }, { "criteria": "cpe:2.3:a:novell:netware:6.5:sp2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DD4DB0F3-97EC-44E8-B9F1-FE2E38B04BCA" }, { "criteria": "cpe:2.3:a:novell:netware:6.5:sp3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CCC810AA-9A2D-488A-989A-57EDA10EE2EB" }, { "criteria": "cpe:2.3:a:novell:netware:6.5:sp4:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D3344514-41C7-40CA-A29F-7591705AC0DC" }, { "criteria": "cpe:2.3:a:novell:netware:6.5:sp5:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "53FA56AE-ACE2-4D18-AE7D-A23CE95D8FFC" }, { "criteria": "cpe:2.3:a:novell:netware:6.5:sp6:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "23987318-3CAD-429D-854A-9D0CC9630967" } ], "operator": "OR" } ] } ]