LWN.net Logo

XTier: code execution

Package(s):Novell XTier framework CVE #(s):CVE-2011-1710
Created:October 26, 2011 Updated:October 26, 2011
Description: From the SUSE advisory:

Several user supplied header length variables for the HTTP server component in the Novell XTier framework were not size limited, allowing integer overflow attacks to crash the service or potentially execute code.

Alerts:
SUSE SUSE-SU-2011:1185-1 2011-10-26

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds