CVE-2008-5092: Buffer Overflow
Heap-based buffer overflows in Novell eDirectory HTTP protocol stack (HTTPSTK) before 8.8 SP3 have unknown impact and attack vectors related to the (1) HTTP language header and (2) HTTP content-length header.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-5092?
The severity of CVE-2008-5092 is currently not classified, but it is recognized as a heap-based buffer overflow vulnerability that could lead to arbitrary code execution.
How do I fix CVE-2008-5092?
To fix CVE-2008-5092, you should upgrade to Novell eDirectory version 8.8 SP3 or a later version that addresses this vulnerability.
What versions of Novell eDirectory are affected by CVE-2008-5092?
CVE-2008-5092 affects Novell eDirectory versions prior to 8.8 SP3, including versions like 8.7.3.9, 8.6.2, and 8.5.27.
What are the potential impacts of CVE-2008-5092?
The potential impacts of CVE-2008-5092 include crashes and arbitrary code execution due to heap-based buffer overflows triggered by malformed HTTP headers.
Are there any known attack vectors for CVE-2008-5092?
The known attack vectors for CVE-2008-5092 are related to the manipulation of the HTTP language and content-length headers.