Vulnerabilities > CVE-2006-0566 - Unspecified vulnerability in Communigate PRO Core Server 5.0.7
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN communigate
nessus
Summary
The LDAP component in CommuniGate Pro Core Server 5.0.7 allows remote attackers to cause a denial of service (application crash) via LDAP messages that contain Distinguished Names (DN) fields with a large number of elements.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Nessus
NASL family | Windows |
NASL id | COMMUNIGATEPRO_508_LDAP_DOS.NASL |
description | The remote host appears to be running CommuniGate Pro, a commercial email and groupware application. The version of CommuniGate Pro installed on the remote host includes an LDAP server that fails to handle requests with Distinguished Names (DNs) that contain too many elements. A user can leverage this issue to crash not just the LDAP server, but also the entire application on the remote host. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 20889 |
published | 2006-02-13 |
reporter | This script is Copyright (C) 2006-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/20889 |
title | CommuniGate Pro Server < 5.0.8 LDAP Module Field Handling Remote DoS |
code |
|
References
- http://secunia.com/advisories/18701
- http://secunia.com/advisories/18701
- http://securityreason.com/securityalert/416
- http://securityreason.com/securityalert/416
- http://securitytracker.com/id?1015587
- http://securitytracker.com/id?1015587
- http://www.gleg.net/advisory_cg2.shtml
- http://www.gleg.net/advisory_cg2.shtml
- http://www.osvdb.org/22932
- http://www.osvdb.org/22932
- http://www.securityfocus.com/archive/1/423968/100/0/threaded
- http://www.securityfocus.com/archive/1/423968/100/0/threaded
- http://www.stalker.com/CommuniGatePro/History.html
- http://www.stalker.com/CommuniGatePro/History.html
- http://www.vupen.com/english/advisories/2006/0444
- http://www.vupen.com/english/advisories/2006/0444
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24409
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24409