Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

HTTP:NOVELL:DHOST-BOF

Severity

High

Recommended

Yes

Recommended Action

Drop

Category

HTTP

Keywords

Novell eDirectory dhost

Release Date

2010/10/13

Update Number

1791

Supported Platforms

idp-4.0.110090709+, isg-3.1.134269+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+

HTTP: Novell eDirectory dhost Buffer Overflow


A remote code execution vulnerability has been reported in Novell eDirectory. The vulnerability is due to a buffer overflow error in the dhost service when handling HTTP requests. A remote, authenticated attacker can exploit this vulnerability by sending a specially crafted HTTP request to a vulnerable system. Successful exploitation would allow for arbitrary code injection and execution with the privileges of the server process. Code injection that does not result in execution could terminate the service, which could result in a Denial of Service condition.

Extended Description

Novell eDirectory is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data. Attackers can exploit this issue to execute arbitrary code in the context of the affected application. Failed exploit attempts will likely cause denial-of-service conditions. Novell eDirectory 8.8 SP5 is vulnerable; other versions may also be affected.

Affected Products

  • Novell eDirectory 8.8
  • Novell eDirectory 8.8.1
  • Novell eDirectory 8.8.2
  • Novell eDirectory 8.8.2 Ftf2
  • Novell eDirectory 8.8 SP1
  • Novell eDirectory 8.8 SP2
  • Novell eDirectory 8.8 SP3
  • Novell eDirectory 8.8 SP3 FTF3
  • Novell eDirectory 8.8 SP4
  • Novell eDirectory 8.8 SP4 FTF1
  • Novell eDirectory 8.8 SP5

References

  • BugTraq: 36815

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy & Policy
Legal Notices
Copyright© 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out