CVE Vulnerabilities

CVE-2006-4521

Published: Nov 04, 2006 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The BerDecodeLoginDataRequest function in the libnmasldap.so NMAS module in Novell eDirectory 8.8 and 8.8.1 before the Security Services 2.0.3 patch does not properly increment a pointer when handling certain input, which allows remote attackers to cause a denial of service (invalid memory access) via a crafted login request.

Affected Software

NameVendorStart VersionEnd Version
EdirectoryNovell8.8 (including)8.8 (including)
EdirectoryNovell8.8.1 (including)8.8.1 (including)

References