Novell eDirectory NCP Get Extension Information Request Remote Heap Memory Corruption Vulnerability
BID:31956
Info
Novell eDirectory NCP Get Extension Information Request Remote Heap Memory Corruption Vulnerability
| Bugtraq ID: | 31956 |
| Class: | Unknown |
| CVE: |
CVE-2008-5038 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 28 2008 12:00AM |
| Updated: | Apr 16 2015 05:52PM |
| Credit: | An anonymous source disclosed this issue. |
| Vulnerable: |
Novell eDirectory 8.8 SP2 Novell eDirectory 8.8 SP1 Novell eDirectory 8.8 |
| Not Vulnerable: | |
Discussion
Novell eDirectory NCP Get Extension Information Request Remote Heap Memory Corruption Vulnerability
Novell eDirectory is prone to a heap-based remote memory-corruption vulnerability.
Successful exploits will allow attackers to corrupt process memory, which will likely cause a denial-of-service condition or allow arbitrary code to run.
This issue is tracked by Novell Bug 373852.
This issue affects eDirectory 8.8 SP2 running on Microsoft Windows; additional versions and platforms may also be affected.
Novell eDirectory is prone to a heap-based remote memory-corruption vulnerability.
Successful exploits will allow attackers to corrupt process memory, which will likely cause a denial-of-service condition or allow arbitrary code to run.
This issue is tracked by Novell Bug 373852.
This issue affects eDirectory 8.8 SP2 running on Microsoft Windows; additional versions and platforms may also be affected.
Exploit / POC
Novell eDirectory NCP Get Extension Information Request Remote Heap Memory Corruption Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Novell eDirectory NCP Get Extension Information Request Remote Heap Memory Corruption Vulnerability
Solution:
The vendor has released fixes. Please see the references for more information.
Solution:
The vendor has released fixes. Please see the references for more information.
References
Novell eDirectory NCP Get Extension Information Request Remote Heap Memory Corruption Vulnerability
References:
References:
- eDirectory Product Homepage (Novell)
- Novell eDirectory 20080924 (Novell)
- Novell eDirectory 20080924 (Novell)
- iDefense Security Advisory 10.30.08: Novell eDirectory NCP Get Extension Informa ("[email protected]"
) - Novell eDirectory NCP Get Extension Information Request Memory Corruption Vulner (iDefense Labs)