|
Novell eDirectory Host Environment HTTP Request Processing Denial of Service
|
|
|
|
|
Secunia Advisory:
|
SA29639
|
|
|
Release Date:
|
2008-04-03
|
|
Last Update:
|
2008-04-15
|
|
|
Critical:
|

Less critical
|
|
Impact:
|
DoS
|
|
Where:
|
From local network
|
|
Solution Status:
|
Unpatched
|
|
| Software: | Novell eDirectory 8.x
|
| | CVE reference: | CVE-2008-1777 (Secunia mirror)
|
|
|
This advisory is currently marked as unpatched! - Companies can be alerted when a patch is released! |
|
|
Description: Mati Aharoni has discovered a vulnerability in Novell eDirectory, which can be exploited by malicious people to cause a DoS (Denial of Service).
The vulnerability is caused due to an error in the Novell eDirectory Host Environment service (dhost.exe) when processing HTTP requests. This can be exploited to e.g. cause the service to consume large amounts of CPU resources and stop responding to other requests by sending an overly long, specially crafted HTTP request to default port 8028/TCP.
The vulnerability is confirmed in version 8.8.2. Other versions may also be affected.
Solution: Restrict network access to the service.
Provided and/or discovered by: Mati Aharoni
Changelog: 2008-04-15: Added CVE reference.
Original Advisory: http://www.offensive-security.com/0day/novel-edir.py.txt
|
|
|
|
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|
|
|
|
15 Related Secunia Security Advisories, displaying 10
|
|
|
1. Novell eDirectory "Connection" HTTP Header Processing Denial of Service
|
|
2. Novell eDirectory SOAP eMBox Interface Unauthenticated Actions
|
|
3. Novell eDirectory LDAP delRequest Message Processing Buffer Overflow
|
|
4. Novell eDirectory NMAS Denial Of Service Vulnerability
|
|
5. Novell Products Two Buffer Overflow Vulnerabilities
|
|
6. Novell eDirectory Multiple Vulnerabilities
|
|
7. Novell eDirectory Denial of Service and Password Exposure
|
|
8. Novell eDirectory iMonitor NDS Server Buffer Overflow Vulnerability
|
|
9. Novell eDirectory iMonitor Buffer Overflow Vulnerability
|
|
10. Novell eDirectory NMAS Password Challenge Bypass
|
Show all related advisories
|
|
|
Send Feedback to Secunia
|
|
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.
|
|
|
|