PT-2008-2541 · Novell · Novell Edirectory

Nicob

·

Published

2008-04-14

·

Updated

2018-10-31

·

CVE-2008-0927

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Novell eDirectory versions 8.7.3 before sp10 and 8.8.2
Description The issue allows remote attackers to cause a denial of service, specifically CPU consumption, via an HTTP request. This can be achieved by sending a request with either multiple Connection headers or a single Connection header that contains multiple comma-separated values.
Recommendations For Novell eDirectory version 8.7.3, apply service pack 10 or later to resolve the issue. For Novell eDirectory version 8.8.2, consider restricting access to the dhost.exe component until a patch is available. As a temporary workaround, limit the handling of HTTP requests with multiple Connection headers or comma-separated values in the Connection header to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-0927

Affected Products

Novell Edirectory