CVE-2006-5479: Medium severity Novell eDirectory vulnerability
Published Oct 24, 2006
·Updated
The NCP Engine in Novell eDirectory before 8.7.3.8 FTF1 allows remote attackers to cause an unspecified denial of service via a certain "NCP Fragment."
Affected Software
10 affected components
Novell eDirectory=8.6.2
Novell eDirectory=8.5.27
Novell eDirectory=8.7
Novell eDirectory=8.0
Novell eDirectory=8.7.3
Novell eDirectory=8.5.12a
Novell eDirectory<=8.7.3.8
Novell eDirectory=8.5
Novell eDirectory=8.7.1
Novell eDirectory=8.7.1-sp1
Remediation
Event History
Oct 24, 2006
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Data Sourced
via NVD·08:07 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2006-5479?
CVE-2006-5479 is classified as a denial of service vulnerability in Novell eDirectory.
2
How do I fix CVE-2006-5479?
To fix CVE-2006-5479, you should update Novell eDirectory to version 8.7.3.8 or later.
3
What versions of Novell eDirectory are affected by CVE-2006-5479?
CVE-2006-5479 affects multiple versions including 8.0, 8.5, 8.5.12a, 8.5.27, 8.6.2, 8.7, 8.7.1, and 8.7.3.
4
What kind of attack does CVE-2006-5479 allow?
CVE-2006-5479 allows remote attackers to cause a denial of service through a specific NCP fragment.
5
Is there a workaround for CVE-2006-5479?
There is no documented workaround for CVE-2006-5479; upgrading to a patched version is recommended.