Vulnerabilities > CVE-2008-4478 - Numeric Errors vulnerability in Novell Edirectory

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
novell
CWE-189
critical
nessus

Summary

Multiple integer overflows in dhost.exe in Novell eDirectory 8.8 before 8.8.3, and 8.73 before 8.7.3.10 ftf1, allow remote attackers to execute arbitrary code via a crafted (1) Content-Length header in a SOAP request or (2) Netware Core Protocol opcode 0x0F message, which triggers a heap-based buffer overflow.

Common Weakness Enumeration (CWE)

Nessus

NASL familyMisc.
NASL idEDIRECTORY_873SP10_MULTIPLE_VULNS.NASL
descriptionThe remote host is running eDirectory, a directory service software from Novell. The installed version of Novell eDirectory is affected by multiple heap overflows and denial of service vulnerabilities : - DS module is affected by two heap overflow vulnerabilities (Bugs 407275, 407256). - EMBOX module is affected by two denial of service vulnerabilities (Bugs 407243, 407245).
last seen2020-06-01
modified2020-06-02
plugin id34349
published2008-10-07
reporterThis script is Copyright (C) 2008-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/34349
titleNovell eDirectory < 8.7.3 SP10 FTF1 Multiple Vulnerabilities

Seebug

bulletinFamilyexploit
descriptionBUGTRAQ ID: 31553 CVE ID:CVE-2008-4478 CVE-2008-4479 CVE-2008-4480 CNCVE ID:CNCVE-20084478 CNCVE-20084479 CNCVE-20084480 Novell eDirectory是一款支持轻量目录访问协议(LDAP)并基于目录的身份管理系统。 Novell eDirectory存在多个缓冲区溢出如下: -WEB控制台运行在TCP 8028和8030端口存在一个缺陷,服务器导出WEB接口并接收SOAP连接。当解析SOAP请求中的Content-Length头字段时存在一个整数溢出。整数溢出可导致在之后的内存拷贝操作过程中触发溢出而导致以SYSTEM用户权限执行任意代码。 -WEB控制台运行在TCP 8028和8030端口存在一个缺陷,服务器导出WEB接口并接收SOAP连接。当服务拷贝SOAP请求中的Accept-Language头字段到固定大小的缓冲区时缺少充分边界检查,攻击者发送特殊构建的请求可导致内存拷贝操作中触发溢出而以SYSTEM用户权限执行任意代码。 -负责目录复制的服务dhost.exe默认绑定TCP 524端口,通过Netware Core协议不正确解析opcode 0x0F可导致数学计算错误而触发整数溢出,可导致任意代码执行。 -负责目录复制的服务dhost.exe默认绑定TCP 524端口,通过Netware Core协议不正确解析opcode 0x24可导致数学计算错误而触发整数溢出,可导致任意代码执行。 Novell eDirectory 8.7.3 SP10b Novell eDirectory 8.7.3 10 可参考如下安全公告获得补丁信息: <a href=http://www.novell.com/support/viewContent.do?externalId=3477912 target=_blank>http://www.novell.com/support/viewContent.do?externalId=3477912</a>
idSSV:4183
last seen2017-11-19
modified2008-10-09
published2008-10-09
reporterRoot
titleNovell eDirectory多个缓冲区溢出漏洞