Novell eDirectory iMonitor "Accept-Language" Buffer Overflow Vulnerability


Description   A vulnerability has been identified in Novell eDirectory, which could be exploited by remote attackers to cause a denial of service or compromise a vulnerable system. This issue is caused by a buffer overflow error in iMonitor when handling a malformed "Accept-Language" header, which could be exploited by remote attackers to crash an affected service or execute arbitrary code.
     
Vulnerable Products   Vulnerable Software:
Novell eDirectory versions prior to 8.8 SP3 FTF3Novell eDirectory versions prior to 8.8 SP4 FTF1Novell eDirectory versions prior to 8.7.3.10b Hotfix 1
     
Solution   Upgrade to Novell eDirectory 8.8 SP3 FTF3.Patches for versions 8.7.3 and 8.8.4 will be available shortly.
     
CVE  
     
References   http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5042340.html
http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5042341.html
http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5042342.html
http://lists.grok.org.uk/pipermail/full-disclosure/2009-February/068160.html
     
Vulnerability Manager Detection   No
     
IPS Protection  
ASQ Engine alarm Available Since
Possible buffer overflow in HTTP request/reply
3.2.0
     


 
 
 
 
 Risk level 
Critical 

 Vulnerability First Public Report Date 
2009-02-27 

 Target Type 
Client 

 Possible exploit 
Local & Remote