CVE-2008-5038: Use After Free
Use-after-free vulnerability in the NetWare Core Protocol (NCP) feature in Novell eDirectory 8.7.3 SP10 before 8.7.3 SP10 FTF1 and 8.8 SP2 for Windows allows remote attackers to cause a denial of service and possibly execute arbitrary code via a sequence of "Get NCP Extension Information By Name" requests that cause one thread to operate on memory after it has been freed in another thread, which triggers memory corruption, aka Novell Bug 373852.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2008-5038?
CVE-2008-5038 is categorized as a high severity vulnerability that can lead to denial of service and potential arbitrary code execution.
How do I fix CVE-2008-5038?
To mitigate CVE-2008-5038, you should upgrade to Novell eDirectory versions 8.7.3 SP10 FTF1 or 8.8 SP2 and apply relevant patches.
What software versions are affected by CVE-2008-5038?
CVE-2008-5038 affects Novell eDirectory versions prior to 8.7.3 SP10 FTF1 and 8.8 SP2 including multiple service packs of 8.7.3.
Can CVE-2008-5038 be exploited remotely?
Yes, CVE-2008-5038 can be exploited remotely through a crafted sequence of requests to the affected NCP feature.
What are the potential impacts of CVE-2008-5038?
Exploitation of CVE-2008-5038 can lead to denial of service or unauthorized execution of arbitrary code on the affected system.