Novell eDirectory NCP Packet Processing Remote Heap Overflow Vulnerability
BID:20664
Info
Novell eDirectory NCP Packet Processing Remote Heap Overflow Vulnerability
| Bugtraq ID: | 20664 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-4177 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 22 2006 12:00AM |
| Updated: | Oct 24 2006 04:33AM |
| Credit: | The discoverer wishes to remain anonymous. |
| Vulnerable: |
Novell eDirectory 8.8.1 Novell eDirectory 8.8 |
| Not Vulnerable: | |
Discussion
Novell eDirectory NCP Packet Processing Remote Heap Overflow Vulnerability
The Novell eDirectory server is prone to a heap-overflow vulnerability because it fails to perform sufficient bounds checking on client-supplied data before copying it to a buffer.
An attacker could leverage this issue to have arbitrary code execute with administrative privileges. A successful exploit could result in the complete compromise of the affected system.
eDirectory versions 8.8.1 and 8.8 were reported vulnerable; other versions may be vulnerable as well.
The Novell eDirectory server is prone to a heap-overflow vulnerability because it fails to perform sufficient bounds checking on client-supplied data before copying it to a buffer.
An attacker could leverage this issue to have arbitrary code execute with administrative privileges. A successful exploit could result in the complete compromise of the affected system.
eDirectory versions 8.8.1 and 8.8 were reported vulnerable; other versions may be vulnerable as well.
Exploit / POC
Novell eDirectory NCP Packet Processing Remote Heap Overflow Vulnerability
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Novell eDirectory NCP Packet Processing Remote Heap Overflow Vulnerability
Solution:
Novell has released fixes to address this issue. Please contact the vendor for more information.
Solution:
Novell has released fixes to address this issue. Please contact the vendor for more information.
References
Novell eDirectory NCP Packet Processing Remote Heap Overflow Vulnerability
References:
References:
- eDirectory Product Homepage (Novell)
- iDefense Security Advisory 10.21.06: Novell eDirectory NCP over IP length Heap O (iDefense Labs
)