First published: Mon Jul 14 2008(Updated: )
Heap-based buffer overflow in Novell eDirectory 8.7.3 before 8.7.3.10b, and 8.8 before 8.8.2 FTF2, allows remote attackers to execute arbitrary code via an LDAP search request containing "NULL search parameters."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microfocus eDirectory | =8.7.3 | |
Microfocus eDirectory | =8.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2008-1809 is high due to its potential for remote code execution.
Fix CVE-2008-1809 by updating Novell eDirectory to version 8.7.3.10b or 8.8.2 FTF2 or later.
CVE-2008-1809 affects Novell eDirectory versions 8.7.3 before 8.7.3.10b and 8.8 before 8.8.2 FTF2.
CVE-2008-1809 is caused by a heap-based buffer overflow triggered by an LDAP search request with NULL search parameters.
CVE-2008-1809 can be exploited by remote attackers with the ability to send specific LDAP search requests.