Vulnerabilities > CVE-2009-0192 - Numeric Errors vulnerability in Novell Edirectory 8.8
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Off-by-one error in the iMonitor component in Novell eDirectory 8.8 SP3, 8.8 SP3 FTF3, and possibly other versions allows remote attackers to execute arbitrary code via an HTTP request with a crafted Accept-Language header, which triggers a stack-based buffer overflow.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
Common Weakness Enumeration (CWE)
Exploit-Db
description | Novell eDirectory iMonitor (Accept-Language) Request BOF PoC. CVE-2009-0192. Dos exploit for windows platform |
id | EDB-ID:8129 |
last seen | 2016-02-01 |
modified | 2009-03-02 |
published | 2009-03-02 |
reporter | Praveen Darshanam |
source | https://www.exploit-db.com/download/8129/ |
title | Novell eDirectory iMonitor Accept-Language Request BoF PoC |
Nessus
NASL family | Misc. |
NASL id | EDIRECTORY_88SP5_MULTIPLE_VULNS.NASL |
description | The remote host is running eDirectory, a directory service software from Novell. The installed version of this software is affected by multiple issues : - Malformed bind LDAP packet causes eDir crash. (Bug 492692) - The use of multiple wildcards in RDNs can trigger a remote denial of service vulnerability. (Bug 458504) - An HTTP request containing a specially crafted |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 39805 |
published | 2009-07-15 |
reporter | This script is Copyright (C) 2009-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/39805 |
title | Novell eDirectory < 8.8 SP5 Multiple Vulnerabilities |
code |
|
Seebug
bulletinFamily | exploit |
description | BUGTRAQ ID: 35666 CVE(CAN) ID: CVE-2009-0192 Novell eDirectory是一个的跨平台的目录服务器。 eDirectory的iMonitor组件在处理HTTP请求时存在栈溢出漏洞。如果攻击者发送了带有畸形Accept-Language头的HTTP请求,就可以触发这个溢出,导致服务器崩溃。 此外RDN中的多个通配符和LDAP报文也可能导致拒绝服务的情况。 Novell eDirectory 8.8 SP3 FTF3 Novell eDirectory 8.8 SP3 厂商补丁: Novell ------ 目前厂商已经发布了升级补丁以修复这个安全问题,请到厂商的主页下载: http://www.novell.com/support/viewContent.do?externalId=3426981 |
id | SSV:11838 |
last seen | 2017-11-19 |
modified | 2009-07-20 |
published | 2009-07-20 |
reporter | Root |
title | Novell eDirectory多个拒绝服务漏洞 |
References
- http://osvdb.org/55847
- http://osvdb.org/55847
- http://secunia.com/advisories/34160
- http://secunia.com/advisories/34160
- http://secunia.com/secunia_research/2009-13/
- http://secunia.com/secunia_research/2009-13/
- http://www.novell.com/support/viewContent.do?externalId=3426981
- http://www.novell.com/support/viewContent.do?externalId=3426981
- http://www.securityfocus.com/archive/1/504924/100/0/threaded
- http://www.securityfocus.com/archive/1/504924/100/0/threaded
- http://www.securityfocus.com/bid/35666
- http://www.securityfocus.com/bid/35666
- http://www.vupen.com/english/advisories/2009/1883
- http://www.vupen.com/english/advisories/2009/1883
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51703
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51703