Novell eDirectory Multiple Security Vulnerabilities
BID:57038
Info
Novell eDirectory Multiple Security Vulnerabilities
| Bugtraq ID: | 57038 |
| Class: | Unknown |
| CVE: |
CVE-2012-0428 CVE-2012-0429 CVE-2012-0430 CVE-2012-0432 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 24 2012 12:00AM |
| Updated: | Apr 02 2013 03:47PM |
| Credit: | Positive Technologies and vendor |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Novell eDirectory Multiple Security Vulnerabilities
Novell eDirectory is prone to following multiple remote vulnerabilities:
1. A cross-site scripting vulnerability
2. A denial-of-service vulnerability
3. An information-disclosure vulnerability
4. A stack-based buffer-overflow vulnerability
Exploiting these issues could allow an attacker to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, disclose sensitive information, execute arbitrary code, or cause a denial-of-service condition. Other attacks are possible.
Novell eDirectory versions prior to 8.8.7.2 and 8.8.6.7 are vulnerable.
Novell eDirectory is prone to following multiple remote vulnerabilities:
1. A cross-site scripting vulnerability
2. A denial-of-service vulnerability
3. An information-disclosure vulnerability
4. A stack-based buffer-overflow vulnerability
Exploiting these issues could allow an attacker to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site, steal cookie-based authentication credentials, disclose sensitive information, execute arbitrary code, or cause a denial-of-service condition. Other attacks are possible.
Novell eDirectory versions prior to 8.8.7.2 and 8.8.6.7 are vulnerable.
Exploit / POC
Novell eDirectory Multiple Security Vulnerabilities
An attacker can exploit some of these issues through a browser.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploits are available:
An attacker can exploit some of these issues through a browser.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following exploits are available:
Solution / Fix
Novell eDirectory Multiple Security Vulnerabilities
Solution:
An update is available. Please see the references for more information.
Solution:
An update is available. Please see the references for more information.
References
Novell eDirectory Multiple Security Vulnerabilities
References:
References:
- eDirectory Product Homepage (Novell)
- Novell Homepage (Novell)