CVE Vulnerabilities

CVE-2008-4478

Published: Oct 14, 2008 | Modified: Oct 11, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Multiple integer overflows in dhost.exe in Novell eDirectory 8.8 before 8.8.3, and 8.73 before 8.7.3.10 ftf1, allow remote attackers to execute arbitrary code via a crafted (1) Content-Length header in a SOAP request or (2) Netware Core Protocol opcode 0x0F message, which triggers a heap-based buffer overflow.

Affected Software

Name Vendor Start Version End Version
Edirectory Novell * 8.7.3.10 (including)
Edirectory Novell 8.7 (including) 8.7 (including)
Edirectory Novell 8.7.1 (including) 8.7.1 (including)
Edirectory Novell 8.7.1-sp1 (including) 8.7.1-sp1 (including)
Edirectory Novell 8.7.3 (including) 8.7.3 (including)
Edirectory Novell 8.7.3.8 (including) 8.7.3.8 (including)
Edirectory Novell 8.7.3.8_presp9 (including) 8.7.3.8_presp9 (including)
Edirectory Novell 8.7.3.9 (including) 8.7.3.9 (including)
Edirectory Novell 8.8 (including) 8.8 (including)
Edirectory Novell 8.8.1 (including) 8.8.1 (including)
Edirectory Novell 8.8.2 (including) 8.8.2 (including)

References