A vulnerability has been identified in Novell eDirectory, which could be exploited by remote attackers to cause a denial of service or compromise a vulnerable system. This issue is caused by a buffer overflow error in iMonitor when handling a malformed "Accept-Language" header, which could be exploited by remote attackers to crash an affected service or execute arbitrary code.
Vulnerable Products
Vulnerable Software: Novell eDirectory versions prior to 8.8 SP3 FTF3Novell eDirectory versions prior to 8.8 SP4 FTF1Novell eDirectory versions prior to 8.7.3.10b Hotfix 1
Solution
Upgrade to Novell eDirectory 8.8 SP3 FTF3.Patches for versions 8.7.3 and 8.8.4 will be available shortly.