First published: Sat Nov 04 2006(Updated: )
The BerDecodeLoginDataRequest function in the libnmasldap.so NMAS module in Novell eDirectory 8.8 and 8.8.1 before the Security Services 2.0.3 patch does not properly increment a pointer when handling certain input, which allows remote attackers to cause a denial of service (invalid memory access) via a crafted login request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microfocus eDirectory | =8.8 | |
Microfocus eDirectory | =8.8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-4521 has a medium severity rating due to its potential to cause denial of service through invalid memory access.
To fix CVE-2006-4521, apply the Security Services 2.0.3 patch for Novell eDirectory versions 8.8 and 8.8.1.
CVE-2006-4521 affects Novell eDirectory versions 8.8 and 8.8.1.
Yes, CVE-2006-4521 can be exploited remotely by attackers to cause denial of service.
CVE-2006-4521 is a denial of service vulnerability caused by improper pointer handling in the NMAS module.