Vulnerabilities > CVE-2008-0927 - Resource Management Errors vulnerability in Microsoft Windows-Nt 2000/2003
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
dhost.exe in Novell eDirectory 8.7.3 before sp10 and 8.8.2 allows remote attackers to cause a denial of service (CPU consumption) via an HTTP request with (1) multiple Connection headers or (2) a Connection header with multiple comma-separated values. NOTE: this might be similar to CVE-2008-1777.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 | |
OS | 2 |
Common Weakness Enumeration (CWE)
Exploit-Db
description | Novell eDirectory < 8.7.3 SP 10 / 8.8.2 HTTP headers DOS Vulnerability. CVE-2008-0927. Dos exploit for windows platform |
file | exploits/windows/dos/5547.txt |
id | EDB-ID:5547 |
last seen | 2016-01-31 |
modified | 2008-05-05 |
platform | windows |
port | |
published | 2008-05-05 |
reporter | Nicob |
source | https://www.exploit-db.com/download/5547/ |
title | Novell eDirectory < 8.7.3 SP 10 / 8.8.2 - HTTP headers DoS Vulnerability |
type | dos |
Nessus
NASL family | Denial of Service |
NASL id | EDIRECTORY_HTTP_CONNECTION_HEADER_DOS.NASL |
description | The remote host is running eDirectory, a directory service software from Novell. The installed version of eDirectory is affected by a denial of service issue. By sending an HTTP request with a specially crafted |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 31863 |
published | 2008-04-16 |
reporter | This script is Copyright (C) 2008-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/31863 |
title | Novell eDirectory Host Environment Service (dhost.exe) HTTP Connection Header DoS |
code |
|
Packetstorm
data source | https://packetstormsecurity.com/files/download/66027/novelledir-dos.txt |
id | PACKETSTORM:66027 |
last seen | 2016-12-05 |
published | 2008-05-06 |
reporter | Nicob |
source | https://packetstormsecurity.com/files/66027/novelledir-dos.txt.html |
title | novelledir-dos.txt |
Seebug
bulletinFamily exploit description BUGTRAQ ID: 28757 CVE(CAN) ID: CVE-2008-0927 Novell eDirectory是一个的跨平台的目录服务器。 Novell eDirectory的dhost.exe服务在处理HTTP请求中的Connection头时存在漏洞,如果远程攻击者向该服务发送了多个特制的HTTP请求的话,就可能导致耗尽大量CPU资源。 Novell eDirectory <= 8.8.1 Novell eDirectory <= 8.7.3.9 Novell ------ 目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载: <a href=http://download.novell.com/ target=_blank>http://download.novell.com/</a> id SSV:3169 last seen 2017-11-19 modified 2008-04-15 published 2008-04-15 reporter Root title Novell eDirectory HTTP Connection头拒绝服务漏洞 bulletinFamily exploit description No description provided by source. id SSV:8416 last seen 2017-11-19 modified 2008-05-10 published 2008-05-10 reporter Root source https://www.seebug.org/vuldb/ssvid-8416 title Novell eDirectory < 8.7.3 SP 10 / 8.8.2 HTTP headers DOS Vulnerability bulletinFamily exploit description No description provided by source. id SSV:65373 last seen 2017-11-19 modified 2014-07-01 published 2014-07-01 reporter Root source https://www.seebug.org/vuldb/ssvid-65373 title Novell eDirectory < 8.7.3 SP 10 / 8.8.2 - HTTP headers DoS Vulnerability
References
- http://www.novell.com/support/viewContent.do?externalId=3829452&sliceId=1
- http://www.securityfocus.com/bid/28757
- http://secunia.com/advisories/29805
- http://www.securitytracker.com/id?1019836
- http://www.vupen.com/english/advisories/2008/1217/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41787
- https://www.exploit-db.com/exploits/5547
- http://www.securityfocus.com/archive/1/491622/100/0/threaded