CVE-2008-4478: Buffer Overflow
Multiple integer overflows in dhost.exe in Novell eDirectory 8.8 before 8.8.3, and 8.73 before 8.7.3.10 ftf1, allow remote attackers to execute arbitrary code via a crafted (1) Content-Length header in a SOAP request or (2) Netware Core Protocol opcode 0x0F message, which triggers a heap-based buffer overflow.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2008-4478?
CVE-2008-4478 has a high severity due to its potential to allow remote code execution.
How do I fix CVE-2008-4478?
To fix CVE-2008-4478, upgrade Novell eDirectory to version 8.8.3 or later.
What types of attacks can exploit CVE-2008-4478?
CVE-2008-4478 can be exploited through crafted SOAP requests or specific Netware Core Protocol messages.
Which versions of Novell eDirectory are affected by CVE-2008-4478?
CVE-2008-4478 affects Novell eDirectory versions 8.7.3.9 and earlier, and all versions prior to 8.8.3.
What are the potential consequences of exploiting CVE-2008-4478?
Exploiting CVE-2008-4478 can lead to arbitrary code execution on the affected system.