First published: Mon Apr 30 2007(Updated: )
ncp in Novell eDirectory before 8.7.3 SP9, and 8.8.x before 8.8.1 FTF2, does not properly handle NCP fragments with a negative length, which allows remote attackers to cause a denial of service (daemon crash) when the heap is written to a log file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Micro Focus NetIQ eDirectory | =8.8 | |
Micro Focus NetIQ eDirectory | <=8.7.3.8 | |
Micro Focus NetIQ eDirectory | =8.8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-4520 has a severity rating that indicates a denial of service could occur due to improper handling of NCP fragments.
To fix CVE-2006-4520, upgrade Novell eDirectory to version 8.7.3 SP9 or 8.8.1 FTF2 or later.
CVE-2006-4520 affects Novell eDirectory versions before 8.7.3 SP9 and 8.8.x before 8.8.1 FTF2.
CVE-2006-4520 is associated with remote denial of service attacks that can crash the daemon.
CVE-2006-4520 primarily causes a denial of service and does not directly expose user data.