First published: Mon Jan 30 2006(Updated: )
CommuniGate Pro Core Server before 5.0.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via LDAP messages with negative BER lengths, and possibly other vectors, as demonstrated by the ProtoVer LDAP test suite.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Communigate Pro | =5.0 | |
Communigate Pro | =5.0.1 | |
Communigate Pro | =5.0.2 | |
Communigate Pro | =5.0.3 | |
Communigate Pro | =5.0.4 | |
Communigate Pro | =5.0.5 | |
Communigate Pro | =5.0.6 | |
Communigate Pro | =5.0c1 | |
Communigate Pro | =5.0c2 | |
Communigate Pro | =5.0c3 | |
Communigate Pro | =5.0c4 | |
Communigate Pro | =5.0c5 | |
Communigate Pro | =5.0c6 | |
Communigate Pro | =5.0c7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-0468 is considered a high severity vulnerability due to its potential to cause denial of service and possibly allow remote code execution.
To mitigate CVE-2006-0468, upgrade to CommuniGate Pro version 5.0.7 or later, where the vulnerability is resolved.
CVE-2006-0468 affects CommuniGate Pro versions 5.0 through 5.0.6.
CVE-2006-0468 allows attackers to exploit LDAP messages with negative BER lengths to cause denial of service or potentially execute arbitrary code.
Yes, CVE-2006-0468 can be exploited remotely, allowing attackers to trigger a server crash or execute code.