Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2008-0924

Опубликовано: 28 мар. 2008
Источник: nvd
CVSS2: 6.8
EPSS Низкий

Описание

Stack-based buffer overflow in the DoLBURPRequest function in libnldap in ndsd in Novell eDirectory 8.7.3.9 and earlier, and 8.8.1 and earlier in the 8.8.x series, allows remote attackers to cause a denial of service (daemon crash or CPU consumption) or execute arbitrary code via a long delRequest LDAP Extended Request message, probably involving a long Distinguished Name (DN) field.

Комментарий

During analysis the following related page was found.

http://www.zerodayinitiative.com/advisories/ZDI-08-013/

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:novell:edirectory:*:*:*:*:*:*:*:*
Версия от 8.7 (включая) до 8.7.3.9 (включая)
cpe:2.3:a:novell:edirectory:*:*:*:*:*:*:*:*
Версия от 8.8 (включая) до 8.8.1 (включая)

EPSS

Процентиль: 88%
0.03886
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-119

Связанные уязвимости

github
почти 4 года назад

Stack-based buffer overflow in the DoLBURPRequest function in libnldap in ndsd in Novell eDirectory 8.7.3.9 and earlier, and 8.8.1 and earlier in the 8.8.x series, allows remote attackers to cause a denial of service (daemon crash or CPU consumption) or execute arbitrary code via a long delRequest LDAP Extended Request message, probably involving a long Distinguished Name (DN) field.

EPSS

Процентиль: 88%
0.03886
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-119