CVE-2006-4521: Medium severity Novell eDirectory vulnerability
The BerDecodeLoginDataRequest function in the libnmasldap.so NMAS module in Novell eDirectory 8.8 and 8.8.1 before the Security Services 2.0.3 patch does not properly increment a pointer when handling certain input, which allows remote attackers to cause a denial of service (invalid memory access) via a crafted login request.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-4521?
CVE-2006-4521 has a medium severity rating due to its potential to cause denial of service through invalid memory access.
How do I fix CVE-2006-4521?
To fix CVE-2006-4521, apply the Security Services 2.0.3 patch for Novell eDirectory versions 8.8 and 8.8.1.
What software is affected by CVE-2006-4521?
CVE-2006-4521 affects Novell eDirectory versions 8.8 and 8.8.1.
Can CVE-2006-4521 be exploited remotely?
Yes, CVE-2006-4521 can be exploited remotely by attackers to cause denial of service.
What type of vulnerability is CVE-2006-4521?
CVE-2006-4521 is a denial of service vulnerability caused by improper pointer handling in the NMAS module.