Vulnerability Description
Stack-based buffer overflow in RpmSrvc.exe in Brooks Remote Print Manager (RPM) 4.5.1.11 and earlier (Elite and Select) for Windows allows remote attackers to execute arbitrary code via a long filename in a "Receive data file" LPD command. NOTE: some of these details are obtained from third party information.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Windows | All versions |
| Brooks Internet Software | Rpm Remote Print Manager Elite | <= 4.5.1.11 |
| Brooks Internet Software | Rpm Remote Print Manager Select | <= 4.5.1.11 |
Related Weaknesses (CWE)
References
- http://aluigi.altervista.org/adv/rpmlpdbof-adv.txt
- http://secunia.com/advisories/28905Vendor Advisory
- http://www.securityfocus.com/archive/1/488010/100/0/threaded
- http://www.securityfocus.com/bid/27742
- http://www.vupen.com/english/advisories/2008/0501
- https://exchange.xforce.ibmcloud.com/vulnerabilities/40432
- http://aluigi.altervista.org/adv/rpmlpdbof-adv.txt
- http://secunia.com/advisories/28905Vendor Advisory
- http://www.securityfocus.com/archive/1/488010/100/0/threaded
- http://www.securityfocus.com/bid/27742
- http://www.vupen.com/english/advisories/2008/0501
- https://exchange.xforce.ibmcloud.com/vulnerabilities/40432
FAQ
What is CVE-2008-0766?
CVE-2008-0766 is a vulnerability with a CVSS score of 10.0 (HIGH). Stack-based buffer overflow in RpmSrvc.exe in Brooks Remote Print Manager (RPM) 4.5.1.11 and earlier (Elite and Select) for Windows allows remote attackers to execute arbitrary code via a long filenam...
How severe is CVE-2008-0766?
CVE-2008-0766 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-0766?
Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Windows, Brooks Internet Software Rpm Remote Print Manager Elite, Brooks Internet Software Rpm Remote Print Manager Select.