First published: Fri Nov 14 2008(Updated: )
Heap-based buffer overflows in Novell eDirectory HTTP protocol stack (HTTPSTK) before 8.8 SP3 have unknown impact and attack vectors related to the (1) HTTP language header and (2) HTTP content-length header.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Novell Edirectory | =8.7.3.9 | |
Novell Edirectory | =8.6.2 | |
Novell Edirectory | =8.5.27 | |
Novell Edirectory | =8.7.3-sp5 | |
Novell Edirectory | =8.7 | |
Novell Edirectory | =8.8 | |
Novell Edirectory | =85.20 | |
Novell Edirectory | =8.8.1 | |
Novell Edirectory | =8.8 | |
Novell Edirectory | =8.0 | |
Novell Edirectory | =8.7.3.9 | |
Novell Edirectory | =8.7.3 | |
Novell Edirectory | =8.7.3-sp4 | |
Novell Edirectory | =8.8 | |
Novell Edirectory | =8.8 | |
Novell Edirectory | =8.7.3-sp1 | |
Novell Edirectory | =8.5.12a | |
Novell Edirectory | =8.8.1 | |
Novell Edirectory | =8.7.3-sp8 | |
Novell Edirectory | <=8.8 | |
Novell Edirectory | =8.8.1 | |
Novell Edirectory | =8.7.3.10 | |
Novell Edirectory | =8.8.2 | |
Novell Edirectory | =8.7.3.9 | |
Novell Edirectory | =8.5 | |
Novell Edirectory | =8.8.2 | |
Novell Edirectory | =8.8.2 | |
Novell Edirectory | =8.7.3-sp3 | |
Novell Edirectory | =8.8.2 | |
Novell Edirectory | =8.7.3-sp6 | |
Novell Edirectory | =8.7.3.9 | |
Novell Edirectory | =8.7.3.8_presp9 | |
Novell Edirectory | =8.8.2 | |
Novell Edirectory | =8.7.1 | |
Novell Edirectory | =8.7.1-sp1 | |
Novell Edirectory | =8.7.3-sp7 | |
Novell Edirectory | =8.7.3.8 | |
Novell Edirectory | =8.8.1 | |
Novell Edirectory | =8.8 | |
Novell Edirectory | =8.8.1 | |
Novell Edirectory | =8.7.3-sp2 | |
Novell Edirectory | =8.7.3-sp9 | |
Novell Edirectory | =8.7.3.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2008-5092 is currently not classified, but it is recognized as a heap-based buffer overflow vulnerability that could lead to arbitrary code execution.
To fix CVE-2008-5092, you should upgrade to Novell eDirectory version 8.8 SP3 or a later version that addresses this vulnerability.
CVE-2008-5092 affects Novell eDirectory versions prior to 8.8 SP3, including versions like 8.7.3.9, 8.6.2, and 8.5.27.
The potential impacts of CVE-2008-5092 include crashes and arbitrary code execution due to heap-based buffer overflows triggered by malformed HTTP headers.
The known attack vectors for CVE-2008-5092 are related to the manipulation of the HTTP language and content-length headers.