CVE Vulnerabilities

CVE-2009-0895

Published: Dec 03, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Integer overflow in Novell eDirectory 8.7.3.x before 8.7.3.10 ftf2 and 8.8.x before 8.8.5.2 allows remote attackers to execute arbitrary code via an NDS Verb 0x1 request containing a large integer value that triggers a heap-based buffer overflow.

Affected Software

NameVendorStart VersionEnd Version
EdirectoryNovell8.7.3 (including)8.7.3 (including)
EdirectoryNovell8.7.3-sp10 (including)8.7.3-sp10 (including)
EdirectoryNovell8.7.3-sp10_b (including)8.7.3-sp10_b (including)
EdirectoryNovell8.7.3-sp3 (including)8.7.3-sp3 (including)
EdirectoryNovell8.7.3-sp4 (including)8.7.3-sp4 (including)
EdirectoryNovell8.7.3-sp5 (including)8.7.3-sp5 (including)
EdirectoryNovell8.7.3.8 (including)8.7.3.8 (including)
EdirectoryNovell8.7.3.9 (including)8.7.3.9 (including)
EdirectoryNovell8.7.3.10 (including)8.7.3.10 (including)
EdirectoryNovell8.8 (including)8.8 (including)
EdirectoryNovell8.8-sp1 (including)8.8-sp1 (including)
EdirectoryNovell8.8-sp2 (including)8.8-sp2 (including)
EdirectoryNovell8.8-sp3 (including)8.8-sp3 (including)
EdirectoryNovell8.8-sp4 (including)8.8-sp4 (including)
EdirectoryNovell8.8.1 (including)8.8.1 (including)
EdirectoryNovell8.8.2 (including)8.8.2 (including)
EdirectoryNovell8.8.5 (including)8.8.5 (including)

References