The evtFilteredMonitorEventsRequest function in the LDAP service in Novell eDirectory before 8.8.1 FTF1 allows remote attackers to execute arbitrary code via a crafted request containing a value that is larger than the number of objects transmitted, which triggers an invalid free of unallocated memory.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Edirectory | Novell | 8.8 (including) | 8.8 (including) |
Edirectory | Novell | 8.8.1 (including) | 8.8.1 (including) |