PT-2008-4578 · Novell · Novell Edirectory
Kingcope
·
Published
2008-07-14
·
Updated
2017-08-08
·
CVE-2008-3159
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Novell eDirectory versions 8.7.3.10 through 8.7.3 SP10b
Novell eDirectory versions 8.8 through 8.8.2 ftf2
Description:
The issue is related to an integer overflow in ds.dlm, used by dhost.exe, which can lead to a stack-based buffer overflow. This is due to flawed arithmetic, allowing remote attackers to execute arbitrary code via unspecified vectors.
Recommendations:
For Novell eDirectory versions 8.7.3.10 through 8.7.3 SP10b, update to version 8.7.3 SP10b or later.
For Novell eDirectory versions 8.8 through 8.8.2 ftf2, update to version 8.8.2 ftf2 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Novell Edirectory