This application requires Javascript for optimal performance.

Novell.eDirectory.LDAP.NULL.Search.Parameter.Buffer.Overflow

Release Date

Oct 14, 2008

Severity

high

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attack attempt against a buffer-overflow vulnerability in Novell eDirectory LDAP Service. The vulnerability is caused by insufficient boundary checking of user-supplied input when allocating a heap buffer to store search parameters.

Affected Products

Novell eDirectory 8.8.2
Novell eDirectory 8.8.1
Novell eDirectory 8.7.3 sp10
Novell eDirectory 8.7.3 9
Novell eDirectory 8.7.3 10
Novell eDirectory 8.7.3 .8 pre-SP9
Novell eDirectory 8.7.3 .8
Novell eDirectory 8.7.3
Novell eDirectory 8.8

Recommended Actions

Apply the latest update from the vendor:
http://download.novell.com/.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2008-1809

Reference/s

http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=724
http://www.securityfocus.com/bid/30175 (BugTraq)

Reference: VID-15721