Vulnerable Systems:
* Novell eDirectory version 8.8 SP3
* Novell eDirectory version 8.8 SP3 FTF3
Immune Systems:
* Novell eDirectory version 8.8 SP5
* Novell eDirectory version 8.8 SP5 FTF3
The vulnerability is caused due to an off-by-one error in the iMonitor component when processing HTTP requests. This can be exploited to cause a stack-based buffer overflow via an HTTP request having a specially crafted "Accept-Language" header.