HTTP: Novell Client Unsafe ActiveX Control

This signature detects attempts to use an unsafe ActiveX control in Novell Client. An attacker can create a malicious Web site containing Web pages with dangerous ActiveX controls, which if accessed by a victim, allows the attacker to gain control of the victim's client browser.

Extended Description

The Novell Client ActiveX control is prone to a remote denial-of-service vulnerability because of an unspecified error. A successful attack allows a remote attacker to crash an application that is using the ActiveX control (typically Internet Explorer), denying further service to legitimate users. Novell Client 4.91.5.1 is vulnerable; other versions may also be affected.

Affected Products

Novell client

Short Name
HTTP:STC:ACTIVEX:NOVELL-CLIENT
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
ActiveX CVE-2009-3038 Client Control Novell Unsafe bid:36139
Release Date
11/05/2012
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown
Vendors

Novell

CVSS Score

4.3

Found a potential security threat?