CVE-2010-4228
Description
Stack-based buffer overflow in NWFTPD.NLM before 5.10.02 in the FTP server in Novell NetWare allows remote authenticated users to execute arbitrary code or cause a denial of service (abend) via a long DELE command, a different vulnerability than CVE-2010-0625.4.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Exploits
Public proof-of-concept code below. AS-IS, for defenders and authorised testing only.
Exploit-DB
Novell Netware - NWFTPD.NLM DELE Remote Code Execution
References
- http://secunia.com/advisories/43824
- http://securityreason.com/securityalert/8149
- http://www.novell.com/support/viewContent.do?externalId=3238588
- http://www.protekresearchlab.com/index.php?option=com_content&view=article&id=25&Itemid=25
- http://www.securityfocus.com/bid/46922
- http://www.zerodayinitiative.com/advisories/ZDI-11-106/
- https://bugzilla.novell.com/show_bug.cgi?id=641249
- https://exchange.xforce.ibmcloud.com/vulnerabilities/66170
- http://secunia.com/advisories/43824
- http://securityreason.com/securityalert/8149
- http://www.novell.com/support/viewContent.do?externalId=3238588
- http://www.protekresearchlab.com/index.php?option=com_content&view=article&id=25&Itemid=25
- http://www.securityfocus.com/bid/46922
- http://www.zerodayinitiative.com/advisories/ZDI-11-106/
- https://bugzilla.novell.com/show_bug.cgi?id=641249
- https://exchange.xforce.ibmcloud.com/vulnerabilities/66170
CWEs
CWE-119
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.