Sploitus

Exploit for Novell iPrint Client ienipp.ocx ActiveX control buffer overflow

saint Β· 2008-06-25

Exploit Code

MARKDOWN32 lines
## https://sploitus.com/exploit?id=SAINT:6F5F92635CAEF2771CAB710C24A87D03
Added: 06/25/2008  
CVE: [CVE-2008-2908](<https://vulners.com/cve/CVE-2008-2908>)  
BID: [29736](<http://www.securityfocus.com/bid/29736>)  
OSVDB: [46194](<http://www.osvdb.org/46194>)  


### Background

Novell iPrint is an application which allows users to install and manage printers. Novell iPrint installs the Novell iPrint Control ActiveX control named `**ienipp.ocx**`. 

### Problem

Multiple buffer overflow vulnerabilities in the Novell iPrint Client allow command execution when a user loads a web page which instantiates the Novell iPrint Control ActiveX control with specially crafted parameters. 

### Resolution

[Upgrade](<http://download.novell.com/Download?buildid=cbAVckbi_AM~>) to Novell iPrint Client 4.36. 

### References

<http://www.kb.cert.org/vuls/id/145313>  
<http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5028061.html>  


### Limitations

Exploit works on Novell iPrint Client 4.34 and requires a user to load the exploit page in Internet Explorer. 

### Platforms

Windows