The xdrDecodeString function in XNFS.NLM in Novell Netware 6.5 before SP8 allows remote attackers to cause a denial of service (abend) or execute arbitrary code via a crafted, signed value in a NFS RPC request to port UDP 1234, leading to a stack-based buffer overflow.
2011-02-25T19:00:00.883
2025-04-11T00:51:21.963
Deferred
CVSSv2: 10.0 (HIGH)
AV:N/AC:L/Au:N/C:C/I:C/A:C
10.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | novell | netware | ≤ 6.5 | Yes |
Application | novell | netware | 6.5 | Yes |
Application | novell | netware | 6.5 | Yes |
Application | novell | netware | 6.5 | Yes |
Application | novell | netware | 6.5 | Yes |
Application | novell | netware | 6.5 | Yes |
Application | novell | netware | 6.5 | Yes |
Application | novell | netware | 6.5 | Yes |