First published: Tue Jul 14 2009(Updated: )
The DS\NDSD component in Novell eDirectory 8.8 before SP5 allows remote attackers to cause a denial of service (ndsd core dump) via an LDAP request containing multiple . (dot) wildcard characters in the Relative Distinguished Name (RDN).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Novell Edirectory | =8.8 | |
Novell Edirectory | =8.8-sp1 | |
Novell Edirectory | =8.8-sp2 | |
Novell Edirectory | =8.8-sp3 | |
Novell Edirectory | =8.8-sp4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-2456 has a medium severity rating due to its potential for denial of service.
CVE-2009-2456 allows remote attackers to cause a denial of service through specially crafted LDAP requests.
To mitigate CVE-2009-2456, upgrade Novell eDirectory to version 8.8 SP5 or later.
CVE-2009-2456 affects Novell eDirectory versions 8.8 up to SP4.
CVE-2009-2456 can lead to a core dump of the ndsd process, resulting in system downtime.