Computer Security
[EN] no-pyccku

Citrix Metaframe Presentation Server / Javvin DiskAccess printer provider buffer overflow
SecurityVulns ID:7109
Threat Level:
Description:Buffer overflow in cpprov.dll EnumPrintersW() and OpenPrinter() functions.
Affected:CITRIX : MetaFrame Presentation Server 3.0
 CITRIX : Metaframe Presentation Server 4.0
 CITRIX : MetaFrame XP 1.0
 JAVVIN : DiskAccess 0.6
CVE:CVE-2007-0641 (Buffer overflow in the EnumPrintersA function in dapcnfsd.dll in Shaffer Solutions (SSC) DiskAccess NFS Client allows remote attackers to execute arbitrary code via a long argument, an issue similar to CVE-2006-5854 and CVE-2007-0444.)
 CVE-2007-0444 (Stack-based buffer overflow in the print provider library (cpprov.dll) in Citrix Presentation Server 4.0, MetaFrame Presentation Server 3.0, and MetaFrame XP 1.0 allows local users and remote attackers to execute arbitrary code via long arguments to the (1) EnumPrintersW and (2) OpenPrinter functions.)
 CVE-2006-5854 (Multiple buffer overflows in the Spooler service (nwspool.dll) in Novell Netware Client 4.91 through 4.91 SP2 allow remote attackers to execute arbitrary code via a long argument to the (1) EnumPrinters and (2) OpenPrinter functions.)
Original documentdocumentZDI, ZDI-07-006: Citrix Metaframe Presentation Server Print Provider Buffer Overflow Vulnerability (25.01.2007)
Files:Universal exploit for vulnerable printer providers (spooler service)
 Proof of concept exploit for ZDI - Citrix Metaframe spooler service vulnerability

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod