Novell eDirectory Multiple Buffer Overflow Vulnerabilities
BID:31553
Info
Novell eDirectory Multiple Buffer Overflow Vulnerabilities
| Bugtraq ID: | 31553 |
| Class: | Unknown |
| CVE: |
CVE-2008-4480 CVE-2008-4478 CVE-2008-4479 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 01 2008 12:00AM |
| Updated: | Oct 09 2008 02:18PM |
| Credit: | Zero Day Initiative |
| Vulnerable: |
Novell eDirectory 8.7.3 SP10b Novell eDirectory 8.7.3.10 |
| Not Vulnerable: |
Novell eDirectory 8.7.3 SP10 FTF1 |
Discussion
Novell eDirectory Multiple Buffer Overflow Vulnerabilities
Novell eDirectory is prone to multiple buffer-overflow vulnerabilities.
Successful exploits may allow attackers to execute arbitrary code within the context of the affected application or to cause denial-of-service conditions.
These issues affect eDirectory 8.7.3 SP10 prior to 8.7.3 SP10 FTF1.
Novell eDirectory is prone to multiple buffer-overflow vulnerabilities.
Successful exploits may allow attackers to execute arbitrary code within the context of the affected application or to cause denial-of-service conditions.
These issues affect eDirectory 8.7.3 SP10 prior to 8.7.3 SP10 FTF1.
Exploit / POC
Novell eDirectory Multiple Buffer Overflow Vulnerabilities
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Novell eDirectory Multiple Buffer Overflow Vulnerabilities
Solution:
The vendor has released fixes. Please see the references for more information.
Solution:
The vendor has released fixes. Please see the references for more information.
References
Novell eDirectory Multiple Buffer Overflow Vulnerabilities
References:
References:
- eDirectory Product Homepage (Novell)
- ZDI-08-063: Novell eDirectory dhost.exe Content-Length Header Heap Overflow Vuln ([email protected])
- ZDI-08-064: Novell eDirectory dhost.exe Accept Language Header Heap Overflow Vul ([email protected])
- ZDI-08-065: Novell eDirectory Core Protocol Opcode 0x0F Heap Overflow Vulnerabil ([email protected])
- ZDI-08-066: Novell eDirectory Core Protocol Opcode 0x24 Heap Overflow Vulnerabil ([email protected])
- 3477912 - History of Issues resolved in eDirectory 8.7.3 patches (Novell)
- ZDI-08-063 Novell eDirectory dhost.exe Content-Length Header Heap Overflow Vulne (ZDI)
- ZDI-08-064 Novell eDirectory dhost.exe Accept Language Header Heap Overflow Vuln (ZDI)
- ZDI-08-065 Novell eDirectory Core Protocol Opcode 0x0F Heap Overflow Vulnerabili (ZDI)
- ZDI-08-066 Novell eDirectory Core Protocol Opcode 0x24 Heap Overflow Vulnerabili (ZDI)