cbcvebase.
CVE-2011-4191
published 2011-11-30

CVE-2011-4191: Stack-based buffer overflow in the xdrDecodeString function in XNFS.NLM in Novell NetWare 6.5 SP8 allows remote attackers to execute arbitrary code or cause a…

PriorityP355high7.5CVSS 2.0
AVNACLAuNCPIPAP
EXPLOIT
EPSS
10.38%
95.2th percentile
Stack-based buffer overflow in the xdrDecodeString function in XNFS.NLM in Novell NetWare 6.5 SP8 allows remote attackers to execute arbitrary code or cause a denial of service (abend or NFS outage) via long packets.

Affected

1 ranges
VendorProductVersion rangeFixed in
novellnetware

Detection & IOCsextracted from sources · hover to see the quote

portUDP/2049
portUDP/32779
portUDP/32778
portTCP/32778
filenameXNFS.NLM
bytes
\x1c\xd1\xef\xab\x00\x00\x00\x00\x00\x00\x00\x02\x00\x01\x86\xa3\x00\x00\x00\x02\x00\x00\x00\x0b
bytes
\x1c\xd1\xef\xab\x00\x00\x00\x00\x00\x00\x00\x02\x00\x01\x86\xb5\x00\x00\x00\x01\x00\x00\x00\x01
bytes
\x1c\xd1\xef\xab\x00\x00\x00\x00\x00\x00\x00\x02\x00\x01\x86\xb8\x00\x00\x00\x01\x00\x00\x00\x06
  • Detect oversized NFS RENAME (procedure 11) RPC requests over UDP/2049 targeting Novell NetWare XNFS.NLM; the exploit uses a fixed XID of 0x1cd1efab and RPC program 100003 (NFS v2).
  • Detect oversized NLM TEST (procedure 1) RPC requests over UDP/32779 targeting Novell NetWare XNFS.NLM; the exploit uses a fixed XID of 0x1cd1efab and RPC program 100021 (NLM v1), with an oversized caller_name field.
  • Detect oversized STAT NOTIFY (procedure 6) RPC requests over UDP or TCP port 32778 targeting Novell NetWare XNFS.NLM; the exploit uses a fixed XID of 0x1cd1efab and RPC program 100024 (STATUS v1).
  • Authentication is not required to exploit this vulnerability; flag any unauthenticated (null credential/verifier) RPC calls to the above programs/procedures on the listed ports from external sources.
  • ·Vulnerability is specific to Novell NetWare 6.5 SP8 only; other versions are not confirmed affected.
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.