CVE-2008-4479: Buffer Overflow
Published Oct 14, 2008
·Updated
Heap-based buffer overflow in dhost.exe in Novell eDirectory 8.8 before 8.8.3, and 8.7.3 before 8.7.3.10 ftf1, allows remote attackers to execute arbitrary code via a SOAP request with a long Accept-Language header.
Affected Software
2 affected components
Novell eDirectory>=8.7.3<8.7.3.10
Novell eDirectory>=8.8<8.8.3
Remediation
Event History
Oct 14, 2008
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-4479?
CVE-2008-4479 has a high severity rating due to the potential for remote code execution.
2
How do I fix CVE-2008-4479?
To fix CVE-2008-4479, upgrade to Novell eDirectory version 8.8.3 or 8.7.3.10 ftf1 or later.
3
What causes the CVE-2008-4479 vulnerability?
CVE-2008-4479 is caused by a heap-based buffer overflow in dhost.exe when processing overly long Accept-Language headers in SOAP requests.
4
Which versions of Novell eDirectory are affected by CVE-2008-4479?
CVE-2008-4479 affects Novell eDirectory versions earlier than 8.8.3 and 8.7.3 versions prior to 8.7.3.10 ftf1.
5
Can CVE-2008-4479 be exploited remotely?
Yes, CVE-2008-4479 can be exploited remotely via malicious SOAP requests.