[NT] Novell iPrint Client ActiveX Control Multiple Vulnerabilities

SecuriTeam <[email protected]> 29 Aug 2008 11:03:22 +0200
Newsgroups gmane.comp.security.securiteam
Message-ID <[email protected]>
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion

The SecuriTeam alerts list - Free, Accurate, Independent.

Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html 

- - - - - - - - -



  Novell iPrint Client ActiveX Control Multiple Vulnerabilities
------------------------------------------------------------------------


SUMMARY

"Neither you nor your users have time to devote to a complex printing 
environment. That's why  
<http://www.novell.com/products/openenterpriseserver/iprint.html> Novell 
iPrint extends print services securely across multiple networks and 
operating systems. Using proven Internet technologies, iPrint transforms 
your Novell Distributed Print Services (NDPS) printers into Net-enabled 
printers, making all your printing resources instantly accessible with a 
Web browser and a few mouse clicks". Multiple vulnerabilities have been 
discovered in Novell's iPrint ActiveX.

DETAILS

Vulnerable Systems:
 * Novell iPrint Client version 4.36
 * Novell iPrint Client for Windows Vista version 5.04

Immune Systems:
 * Novell iPrint Client version 5.06

Novell iPrint Client ActiveX Control "GetFileList()" Information 
Disclosure
Secunia Research has discovered a security issue in Novell iPrint Client, 
which can be exploited by malicious people to gain knowledge of 
potentially sensitive information.

The insecure "GetFileList()" method returns a list of images (".jpg", 
".jpeg", ".gif", and ".bmp") in a directory specified as argument to the 
method. This can be exploited to gain knowledge of any image file names in 
arbitrary directories on a user's system, including e.g. the user's "My 
Pictures" / "Pictures" folder without knowledge of the user's username.

Solution:
Update to version 5.06.

Time Table:
20/06/2008 - Vendor notified.
23/06/2008 - Vendor response.
07/07/2008 - Vendor reports that vulnerability has been addressed.
08/07/2008 - Vendor provides new version for testing.
08/07/2008 - Vendor informed that vulnerability is not fixed.
10/07/2008 - Details on vulnerability forwarded.
21/07/2008 - Vendor reports that vulnerability was missed and that a new 
tracking number will be generated.
22/08/2008 - Vendor issues fixed version for Vista.
25/08/2008 - Public disclosure.

CVE Information:
 <http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2432> 
CVE-2008-2432

Novell iPrint Client ActiveX Control Multiple Buffer Overflows
Secunia Research has discovered multiple vulnerabilities in Novell iPrint 
Client, which can be exploited by malicious people to compromise a user's 
system.

1) A boundary error in the Novell iPrint ActiveX control (ienipp.ocx) when 
handling the "GetDriverFile()" method can be exploited to cause a 
stack-based buffer overflow by passing an overly long string as the  third 
argument.

2) Two boundary errors in the Novell iPrint ActiveX control (ienipp.ocx) 
when constructing a URI based on input to the "GetPrinterURLList()" and 
"GetPrinterURLList2()" methods can be exploited to cause limited 
stack-based buffer overflows via an overly long string passed as the 1st 
argument.

3) A boundary error in the Novell iPrint ActiveX control (ienipp.ocx) when 
handling the "GetFileList()" method can be exploited to cause a heap-based 
buffer overflow via an overly long argument.

4) Various boundary errors in nipplib.dll when e.g. creating a server 
reference or interpreting a URI can be exploited to cause stack-based and 
heap-based buffer overflows by e.g. passing an overly long string as 
argument to the "GetServerVersion()", "GetResourceList()", or 
"DeleteResource()" methods provided by the Novell iPrint ActiveX control 
(ienipp.ocx).

5) Boundary errors in the Novell iPrint ActiveX control (ienipp.ocx) when 
constructing a URI based on input to the "UploadPrinterDriver()" and 
"UploadResource()" methods can be exploited to cause a heap-based buffer 
overflow and limited stack-based buffer overflow via an overly long, 
specially crafted "uploadPath" argument.

6) A boundary error in the Novell iPrint ActiveX control (ienipp.ocx) when 
copying "target-frame" option values passed to the "ExecuteRequest()" 
method can be exploited to cause a limited stack-based buffer overflow via 
an overly long "target-frame" option value.

7) A boundary error in the Novell iPrint ActiveX control (ienipp.ocx) when 
handling the "UploadResource()" method can be exploited to cause a 
stack-based buffer overflow by passing an overly long string as the 7th 
argument.

8) Three boundary errors in nipplib.dll within the 
"IppGetDriverSettings()" function can be exploited to cause stack-based 
buffer overflows by passing an overly long string as the 2nd, 3rd, or 4th 
argument of the "GetDriverSettings()" method provided by Novell iPrint 
ActiveX control (ienipp.ocx).

9) A boundary error in the Novell iPrint ActiveX control (ienipp.ocx) when 
handling the "UploadResourceToRMS" method can be exploited to cause a 
stack-based buffer overflow by passing an overly long string as the 8th 
argument.

Solution:
The vulnerabilities are fixed in version 5.06.

Time Table:
18/06/2008 - Vendor notified (1st batch of vulnerabilities)
18/06/2008 - Vendor response.
23/06/2008 - Vendor notified (2nd batch of vulnerabilities)
23/06/2008 - Vendor response.
27/06/2008 - Vendor notified (3rd batch of vulnerabilities)
27/06/2008 - Vendor response.
07/07/2008 - Vendor reports that vulnerabilities have been addressed.
08/07/2008 - Vendor provides new version for testing.
08/07/2008 - Vendor informed that all vulnerabilities are fixed.
22/08/2008 - Vendor issues fixed version for Vista.
25/08/2008 - Public disclosure.

CVE Information:
 <http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2431> 
CVE-2008-2431


ADDITIONAL INFORMATION

The information has been provided by Secunia Research.
The original article can be found at:  
<http://secunia.com/secunia_research/2008-27/> 
http://secunia.com/secunia_research/2008-27/ and  
<http://secunia.com/secunia_research/2008-30/> 
http://secunia.com/secunia_research/2008-30/



======================================== 


This bulletin is sent to members of the SecuriTeam mailing list. 
To unsubscribe from the list, send mail with an empty subject line and body to: [email protected] 
In order to subscribe to the mailing list, simply forward this email to: [email protected] 


==================== 
==================== 

DISCLAIMER: 
The information in this bulletin is provided "AS IS" without warranty of any kind. 
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.