Environment
Novell iPrint Client for Windows
Situation
Resolution
The fix for this security vulnerability is included in the released "iPrint Client for Windows XP/Vista/Win 7 (English Only) 5.72" patch, or later.
Status
Security AlertAdditional Information
ZDI-CAN-1289: Novell iPrint Client nipplib.dll GetDriverSettings Remote Code Execution Vulnerability. This vulnerability was found by gwslabs.com, working with TippingPoint's Zero Day Initiative. CVE-2011-3173
The flaw exists within the nipplib.dll component. When handling the exposed method GetDriverSettings the application assembles a string for logging consisting of the hostname/port provided as a parameter. When building this message the process will blindly copy user supplied data into a fixed-length buffer on the stack. A remote attacker can exploit this vulnerability to execute arbitrary code under the context of the browser.