Novell eDirectory Server iMonitor Buffer Overflow Vulnerability
BID:14548
Info
Novell eDirectory Server iMonitor Buffer Overflow Vulnerability
| Bugtraq ID: | 14548 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 11 2005 12:00AM |
| Updated: | Aug 11 2005 12:00AM |
| Credit: | Discovered by Peter Winter-Smith of NGSSoftware. |
| Vulnerable: |
Novell eDirectory 8.7.3 |
| Not Vulnerable: | |
Discussion
Novell eDirectory Server iMonitor Buffer Overflow Vulnerability
The Novell eDirectory Server iMonitor is prone to a buffer overflow. Successful exploitation could allow arbitrary code execution with Local System privileges.
eDirectory 8.7.3 iMonitor is vulnerable to this issue. Earlier versions may also be affected.
The Novell eDirectory Server iMonitor is prone to a buffer overflow. Successful exploitation could allow arbitrary code execution with Local System privileges.
eDirectory 8.7.3 iMonitor is vulnerable to this issue. Earlier versions may also be affected.
Exploit / POC
Novell eDirectory Server iMonitor Buffer Overflow Vulnerability
The following exploit is available for Metasploit:
The following exploit is available for Metasploit:
Solution / Fix
Novell eDirectory Server iMonitor Buffer Overflow Vulnerability
Solution:
Novell has released a fix for this issue:
Novell eDirectory 8.7.3
Solution:
Novell has released a fix for this issue:
Novell eDirectory 8.7.3
-
Novell edir873ptf_imon1.exe
http://support.novell.com/servlet/filedownload/sec/pub/edir873ptf_imon 1.exe
References
Novell eDirectory Server iMonitor Buffer Overflow Vulnerability
References:
References:
- Buffer overflow vulnerability against eDirectory 8.7.3 imonitor on Windows - TID (Novell)
- eDirectory 8.7.3 iMonitor for Win32 - TID2972038 (Novell)
- High Risk Vulnerability in Novell eDirectory Server ("NGSSoftware Insight Security Research"
)