Vulnerabilities > CVE-2009-2456 - Unspecified vulnerability in Novell Edirectory 8.8
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN novell
nessus
Summary
The DS\NDSD component in Novell eDirectory 8.8 before SP5 allows remote attackers to cause a denial of service (ndsd core dump) via an LDAP request containing multiple . (dot) wildcard characters in the Relative Distinguished Name (RDN).
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 5 |
Nessus
NASL family | Misc. |
NASL id | EDIRECTORY_88SP5_MULTIPLE_VULNS.NASL |
description | The remote host is running eDirectory, a directory service software from Novell. The installed version of this software is affected by multiple issues : - Malformed bind LDAP packet causes eDir crash. (Bug 492692) - The use of multiple wildcards in RDNs can trigger a remote denial of service vulnerability. (Bug 458504) - An HTTP request containing a specially crafted |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 39805 |
published | 2009-07-15 |
reporter | This script is Copyright (C) 2009-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/39805 |
title | Novell eDirectory < 8.8 SP5 Multiple Vulnerabilities |
code |
|
References
- http://osvdb.org/55848
- http://osvdb.org/55848
- http://secunia.com/advisories/34160
- http://secunia.com/advisories/34160
- http://www.novell.com/support/viewContent.do?externalId=3426981
- http://www.novell.com/support/viewContent.do?externalId=3426981
- http://www.securityfocus.com/bid/35666
- http://www.securityfocus.com/bid/35666
- http://www.vupen.com/english/advisories/2009/1883
- http://www.vupen.com/english/advisories/2009/1883
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51705
- https://exchange.xforce.ibmcloud.com/vulnerabilities/51705