CVE-2006-4517: Null Pointer Dereference
Published Nov 1, 2006
·Updated
Novell iManager 2.5 and 2.0.2 allows remote attackers to cause a denial of service (crash) in the Tomcat server via a long TREE parameter in an HTTP POST, which triggers a NULL pointer dereference.
Affected Software
4 affected components
Novell iManager=2.0.2
Novell iManager=2.0
Novell iManager=1.5
Novell iManager<=2.5
Remediation
Patch Available
Patch Available
Event History
Nov 1, 2006
CVE Published
03:07 PM
Data Sourced
via NVD·03:07 PM
RemedyDescriptionSeverityWeaknessAffected Software
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-4517?
CVE-2006-4517 has a moderate severity rating due to its ability to cause a denial of service.
2
How do I fix CVE-2006-4517?
To fix CVE-2006-4517, you should update your Novell iManager software to version 2.5 or later.
3
What versions of Novell iManager are affected by CVE-2006-4517?
CVE-2006-4517 affects Novell iManager versions 1.5, 2.0, and 2.0.2, up to version 2.5.
4
What kind of attack does CVE-2006-4517 allow?
CVE-2006-4517 allows remote attackers to crash the Tomcat server through a specially crafted HTTP POST request.
5
Is there a known exploit for CVE-2006-4517?
Yes, there have been reports of exploits targeting CVE-2006-4517 that leverage long TREE parameters.