|
|
|
|
| |
Credit:
The information has been provided by The Zero Day Initiative (ZDI).
The original article can be found at: http://www.zerodayinitiative.com/advisories/ZDI-08-013
|
| |
Vulnerable Systems:
* Novell eDirectory version 8.8.1
* Novell eDirectory version 8.7.3.9 (8.7.3 SP9)
Immune Systems:
* Novell eDirectory version 8.8.2
* Novell eDirectory version 8.7.3.10 (8.7.3 SP10)
The specific flaw exists in the libnldap library. When a large LDAP delRequest message is sent, a stack overflow occurs overwriting a function pointer. This results in a situation allowing the execution of arbitrary code.
Vendor Response:
Novell has issued an update to correct this vulnerability. More details can be found at:
http://www.novell.com/support/search.do?cmd=displayKC&docType=kc&externalId=3382120&sliceId=SAL_Public&dialogID=59352034&stateId=0%200%2059350122
Disclosure Timeline:
2007-07-20 - Vulnerability reported to vendor
2008-03-26 - Coordinated public release of advisory
CVE Information:
CVE-2008-0924
|
|
|
|
|