CVE-2006-4509: Integer Overflow
Published Oct 24, 2006
·Updated
Integer overflow in the evtFilteredMonitorEventsRequest function in the LDAP service in Novell eDirectory before 8.8.1 FTF1 allows remote attackers to execute arbitrary code via a crafted request.
Affected Software
2 affected components
Novell eDirectory=8.8
Novell eDirectory=8.8.1
Remediation
Patch Available
Patch Available
Event History
Oct 24, 2006
CVE Published
07:07 PM
Data Sourced
via NVD·07:07 PM
RemedyDescriptionSeverityAffected Software
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-4509?
CVE-2006-4509 is considered critical as it allows remote attackers to execute arbitrary code.
2
How do I fix CVE-2006-4509?
To fix CVE-2006-4509, upgrade Novell eDirectory to version 8.8.1 FTF1 or later.
3
Which versions of Novell eDirectory are affected by CVE-2006-4509?
CVE-2006-4509 affects Novell eDirectory versions 8.8 and 8.8.1 before FTF1.
4
Can CVE-2006-4509 be exploited remotely?
Yes, CVE-2006-4509 can be exploited remotely by sending a crafted request to the LDAP service.
5
What type of attack does CVE-2006-4509 facilitate?
CVE-2006-4509 facilitates remote code execution attacks through an integer overflow vulnerability.