Novell eDirectory HTTP 'Connection' Header Denial Of Service Vulnerability
BID:28757
Info
Novell eDirectory HTTP 'Connection' Header Denial Of Service Vulnerability
| Bugtraq ID: | 28757 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2008-0927 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 11 2008 12:00AM |
| Updated: | May 05 2008 11:05PM |
| Credit: | Nicholas Gregorie |
| Vulnerable: |
Novell eDirectory 8.8.1 Novell eDirectory 8.7.3 .8 pre-SP9 Novell eDirectory 8.7.3 .8 Novell eDirectory 8.7.3 Novell eDirectory 8.8 Novell eDirectory 8.7.3.9 |
| Not Vulnerable: |
Novell eDirectory 8.8.2 Novell eDirectory 8.7.3 sp10 |
Discussion
Novell eDirectory HTTP 'Connection' Header Denial Of Service Vulnerability
Novell eDirectory is prone to a denial-of-service vulnerability when handling requests with specially crafted HTTP 'Connection' headers.
Remote attackers can exploit this issue to deny service to legitimate users.
The issue affects versions prior to eDirectory 8.8.2 and prior to eDirectory 8.7.3 sp10 for Windows 2000/2003 systems.
Novell eDirectory is prone to a denial-of-service vulnerability when handling requests with specially crafted HTTP 'Connection' headers.
Remote attackers can exploit this issue to deny service to legitimate users.
The issue affects versions prior to eDirectory 8.8.2 and prior to eDirectory 8.7.3 sp10 for Windows 2000/2003 systems.
Exploit / POC
Novell eDirectory HTTP 'Connection' Header Denial Of Service Vulnerability
An attacker can exploit this issue by using readily available network utilities.
The following proof of concept is available:
An attacker can exploit this issue by using readily available network utilities.
The following proof of concept is available:
Solution / Fix
Novell eDirectory HTTP 'Connection' Header Denial Of Service Vulnerability
Solution:
The vendor has released updates. Please see the references for more information.
Solution:
The vendor has released updates. Please see the references for more information.
References
Novell eDirectory HTTP 'Connection' Header Denial Of Service Vulnerability
References:
References:
- Novell Homepage (Novell)
- Novell eDirectory DoS via HTTP headers (Nicob
) - Security Vulnerability - DoS via 'Connection:' HTTP headers (Novell)