|
Brought to you by:
Suppliers of:
|
|
|
| |
| A vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Novell eDirectory. Authentication is not required to exploit this vulnerability. |
| |
Credit:
The information has been provided by TippingPoint, The Zero Day Initiative (ZDI).
The original article can be found at: http://www.zerodayinitiative.com/advisories/ZDI-08-041
|
| |
Vulnerable Systems:
* Novell eDirectory version 8.8 for All Platforms
* Novell eDirectory version 8.7.3 for All Platforms
The specific flaw exists within dhost.exe, bound by default to TCP port 524. Flawed arithmetic applied to a user-supplied value results in an integer overflow and subsequently a complete stack smash allowing an attacker to execute arbitrary code via SEH redirection.
Vendor Response:
Novell has issued an update to correct this vulnerability. More details can be found at:
http://www.novell.com/support/search.do?cmd=displayKC&sliceId=SAL_Public&externalId=3694858
Solution:
To resolve this issue in eDirectory 8.8.2:
* Apply eDir 8.8.2 ftf2 or later
To resolve this issue in eDirectory 8.7.3:
* Apply eDir 8.7.3 SP10b or later
Disclosure Timeline:
2007-12-04 - Vulnerability reported to vendor
2008-07-10 - Coordinated public release of advisory
|
|
|
|
|