First published: Tue Oct 24 2006(Updated: )
The evtFilteredMonitorEventsRequest function in the LDAP service in Novell eDirectory before 8.8.1 FTF1 allows remote attackers to execute arbitrary code via a crafted request containing a value that is larger than the number of objects transmitted, which triggers an invalid free of unallocated memory.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microfocus eDirectory | =8.8 | |
Microfocus eDirectory | =8.8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-4510 has a high severity rating due to the potential for remote code execution.
To fix CVE-2006-4510, update Novell eDirectory to version 8.8.1 FTF1 or later.
CVE-2006-4510 affects Novell eDirectory versions 8.8 and 8.8.1 prior to FTF1.
CVE-2006-4510 allows remote attackers to execute arbitrary code.
CVE-2006-4510 is caused by improper handling of crafted requests in the LDAP service.