Novell eDirectory iMonitor HTTPSTK Buffer Overflow Vulnerability
BID:20655
Info
Novell eDirectory iMonitor HTTPSTK Buffer Overflow Vulnerability
| Bugtraq ID: | 20655 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-5478 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 21 2006 12:00AM |
| Updated: | Nov 26 2009 05:45PM |
| Credit: | Michael Ligh and Ryan Smith are credited with the discovery of this issue. Manuel Santamarina Suarez may have also independently discovered this issue. |
| Vulnerable: |
Novell eDirectory 8.8.1 Novell eDirectory 8.7.3 .8 pre-SP9 Novell eDirectory 8.7.3 .8 Novell eDirectory 8.7.3 Novell eDirectory 8.7.1 SU1 Novell eDirectory 8.7.1 Novell eDirectory 8.7 Novell eDirectory 8.6.2 Novell eDirectory 8.5.27 Novell eDirectory 8.5.12 a Novell eDirectory 8.5 Novell eDirectory 8.0 Novell eDirectory 8.8 |
| Not Vulnerable: | |
Discussion
Novell eDirectory iMonitor HTTPSTK Buffer Overflow Vulnerability
The Novell eDirectory server iMonitor is prone to a stack-based buffer-overflow vulnerability because it fails to perform sufficient bounds checking on client-supplied data before copying it to a buffer.
An attacker could leverage this issue to execute arbitrary code with administrative privileges. A successful exploit could result in the complete compromise of the affected system.
The Novell eDirectory server iMonitor is prone to a stack-based buffer-overflow vulnerability because it fails to perform sufficient bounds checking on client-supplied data before copying it to a buffer.
An attacker could leverage this issue to execute arbitrary code with administrative privileges. A successful exploit could result in the complete compromise of the affected system.
Exploit / POC
Novell eDirectory iMonitor HTTPSTK Buffer Overflow Vulnerability
UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
A proof of concept is available. Please see the references for more information.
A Metasploit Framework exploit module and other exploits are available.
UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
A proof of concept is available. Please see the references for more information.
A Metasploit Framework exploit module and other exploits are available.
Solution / Fix
Novell eDirectory iMonitor HTTPSTK Buffer Overflow Vulnerability
Solution:
Novell is addressing this issue with FTF packages. Please see the references for details.
Solution:
Novell is addressing this issue with FTF packages. Please see the references for details.
References
Novell eDirectory iMonitor HTTPSTK Buffer Overflow Vulnerability
References:
References:
- eDirectory Post 8.7.3.8 FTF1 HTTPSTK (Novell)
- eDirectory Post 8.8.1 FTF1 for Linux\Unix (Novell)
- eDirectory Post 8.8.1 FTF1 for NW & Win32 (Novell)
- eDirectory Product Homepage (Novell)
- Novell eDirectory NDS Server Host Header Buffer Overflow Vulnerability (Zero Day Initiative)
- Novell eDirectory/iMonitor Remote Code Execution Security Advisory (Michael Ligh and Ryan Smith)
- Security Vulnerability: Remote code Execution in iMonitor (Novell)