Vulnerabilities > CVE-2006-0468 - Denial of Service vulnerability in Communigate Pro Server LDAP
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
CommuniGate Pro Core Server before 5.0.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via LDAP messages with negative BER lengths, and possibly other vectors, as demonstrated by the ProtoVer LDAP test suite.
Vulnerable Configurations
Exploit-Db
description | Communigate Pro 5.0.6 Server LDAP Denial of Service Vulnerability. CVE-2006-0468. Dos exploit for linux platform |
id | EDB-ID:27144 |
last seen | 2016-02-03 |
modified | 2006-01-28 |
published | 2006-01-28 |
reporter | Evgeny Legerov |
source | https://www.exploit-db.com/download/27144/ |
title | Communigate Pro 5.0.6 Server LDAP Denial of Service Vulnerability |
Nessus
NASL family | Windows |
NASL id | COMMUNIGATEPRO_LDAP_DOS.NASL |
description | The remote host appears to be running CommuniGate Pro, a commercial email and groupware application. The version of CommuniGate Pro installed on the remote host includes an LDAP server that reportedly fails to handle requests with negative BER lengths. A user can leverage this issue to crash not just the LDAP server but also the entire application on the remote host. Remote code execution may even be possible. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 20827 |
published | 2006-01-31 |
reporter | This script is Copyright (C) 2006-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/20827 |
title | CommuniGate Pro Server < 5.0.7 LDAP BER Decoding Multiple Vulnerabilities |
code |
|
References
- http://secunia.com/advisories/18640
- http://www.gleg.net/advisory_cg.shtml
- http://www.securityfocus.com/archive/1/423364/100/0/threaded
- http://www.securityfocus.com/bid/16407
- http://www.stalker.com/CommuniGatePro/History.html
- http://www.vupen.com/english/advisories/2006/0364
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24409