Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.802674
Kategorie:Denial of Service
Titel:Novell eDirectory Multiple Buffer Overflow Vulnerabilities (CVE-2006-5478) - Active Check
Zusammenfassung:Novell eDirectory is prone to multiple multiple stack based; buffer overflow vulnerabilities.
Beschreibung:Summary:
Novell eDirectory is prone to multiple multiple stack based
buffer overflow vulnerabilities.

Vulnerability Insight:
The flaws are due to improper validation of user-supplied input
via a long HTTP Host header, which triggers an overflow in the BuildRedirectURL function.

Vulnerability Impact:
Successful exploitation will allow remote attackers to execute
arbitrary code and deny the server.

Affected Software/OS:
Novell eDirectory version 8.8.x through 8.8.1 and 8.x through
8.7.3.8 (8.7.3 SP8)

Solution:
Update to version 8.8.1 FTF1, 8.7.3.9 (8.7.3 SP9) or later.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2006-5478
BugTraq ID: 20655
http://www.securityfocus.com/bid/20655
BugTraq ID: 20853
http://www.securityfocus.com/bid/20853
Bugtraq: 20061026 ZDI-06-035: Novell eDirectory NDS Server Host Header Buffer Overflow Vulnerability (Google Search)
http://www.securityfocus.com/archive/1/449899/100/0/threaded
Bugtraq: 20061028 Re: [Full-disclosure] ZDI-06-035: Novell eDirectory NDS Server Host Header Buffer Overflow Vulnerability (Google Search)
http://www.securityfocus.com/archive/1/450017/100/0/threaded
Bugtraq: 20061103 ZDI-06-036: Novell Netmail User Authentication Buffer Overflow Vulnerability (Google Search)
http://www.securityfocus.com/archive/1/450520/100/100/threaded
http://lists.grok.org.uk/pipermail/full-disclosure/2006-October/050382.html
http://lists.grok.org.uk/pipermail/full-disclosure/2006-October/050388.html
http://www.mnin.org/advisories/2006_novell_httpstk.pdf
http://www.zerodayinitiative.com/advisories/ZDI-06-035.html
http://www.zerodayinitiative.com/advisories/ZDI-06-036.html
http://securitytracker.com/id?1017125
http://securitytracker.com/id?1017141
http://secunia.com/advisories/22519
http://www.vupen.com/english/advisories/2006/4141
CopyrightCopyright (C) 2012 Greenbone AG

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.