CVE-2006-4177: Buffer Overflow
Published Oct 24, 2006
·Updated
Heap-based buffer overflow in the NCP engine in Novell eDirectory before 8.8.1 FTF1 allows remote attackers to execute arbitrary code via a crafted NCP over IP packet that causes NCP to read more data than intended.
Affected Software
2 affected components
Novell eDirectory<=8.8.1
Novell eDirectory=8.8
Remediation
Patch Available
Event History
Oct 24, 2006
CVE Published
08:07 PM
Data Sourced
via NVD·08:07 PM
RemedyDescriptionSeverityAffected Software
Oct 25, 2006
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-4177?
CVE-2006-4177 is rated as high severity due to the potential for remote code execution.
2
How do I fix CVE-2006-4177?
To fix CVE-2006-4177, upgrade Novell eDirectory to version 8.8.1 FTF1 or later.
3
Who is affected by CVE-2006-4177?
CVE-2006-4177 affects all versions of Novell eDirectory prior to 8.8.1 FTF1.
4
What type of vulnerability is CVE-2006-4177?
CVE-2006-4177 is a heap-based buffer overflow vulnerability.
5
What can attackers achieve with CVE-2006-4177?
Attackers exploiting CVE-2006-4177 can execute arbitrary code on vulnerable systems.