Novell eDirectory Server Long URI iMonitor Buffer Overflow Vulnerability
BID:18026
CVE-2006-2496 |Info
Novell eDirectory Server Long URI iMonitor Buffer Overflow Vulnerability
| Bugtraq ID: | 18026 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 18 2006 12:00AM |
| Updated: | May 23 2006 03:18PM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
Novell iMonitor 2.4 Novell eDirectory 8.8 |
| Not Vulnerable: | |
Discussion
Novell eDirectory Server Long URI iMonitor Buffer Overflow Vulnerability
The Novell eDirectory Server iMonitor is prone to a buffer-overflow vulnerability. Successfully exploiting this issue could allow arbitrary code execution with administrative privileges.
iMonitor version 2.4, which is included with eDirectory version 8.8, is vulnerable to this issue; other versions may also be affected.
The Novell eDirectory Server iMonitor is prone to a buffer-overflow vulnerability. Successfully exploiting this issue could allow arbitrary code execution with administrative privileges.
iMonitor version 2.4, which is included with eDirectory version 8.8, is vulnerable to this issue; other versions may also be affected.
Exploit / POC
Novell eDirectory Server Long URI iMonitor Buffer Overflow Vulnerability
A Metasploit framework exploit module (edirectory_imonitor2.pm) is available.
A Metasploit framework exploit module (edirectory_imonitor2.pm) is available.
Solution / Fix
Novell eDirectory Server Long URI iMonitor Buffer Overflow Vulnerability
Solution:
Novell has released an advisory, along with a fix to address this issue. Please see the referenced advisory for further information.
Novell iMonitor 2.4
Novell eDirectory 8.8
Solution:
Novell has released an advisory, along with a fix to address this issue. Please see the referenced advisory for further information.
Novell iMonitor 2.4
-
Novell edir88ptf_imon.tgz
http://support.novell.com/servlet/filedownload/sec/pub/edir88ptf_imon. tgz
Novell eDirectory 8.8
-
Novell edir88ptf_imon.tgz
http://support.novell.com/servlet/filedownload/sec/pub/edir88ptf_imon. tgz
References
Novell eDirectory Server Long URI iMonitor Buffer Overflow Vulnerability
References:
References: