CVE-2009-2456: Medium severity micro focus netiq edirectory vulnerability
Published Jul 14, 2009
·Updated
The DS\NDSD component in Novell eDirectory 8.8 before SP5 allows remote attackers to cause a denial of service (ndsd core dump) via an LDAP request containing multiple . (dot) wildcard characters in the Relative Distinguished Name (RDN).
Affected Software
5 affected components
Novell eDirectory=8.8
Novell eDirectory=8.8-sp3
Novell eDirectory=8.8-sp1
Novell eDirectory=8.8-sp4
Novell eDirectory=8.8-sp2
Event History
Jul 14, 2009
CVE Published
via MITRE·08:16 PM
Data Sourced
via MITRE·08:16 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-2456?
CVE-2009-2456 has a medium severity rating due to its potential for denial of service.
2
How does CVE-2009-2456 affect Novell eDirectory?
CVE-2009-2456 allows remote attackers to cause a denial of service through specially crafted LDAP requests.
3
How do I fix CVE-2009-2456?
To mitigate CVE-2009-2456, upgrade Novell eDirectory to version 8.8 SP5 or later.
4
Which versions of Novell eDirectory are affected by CVE-2009-2456?
CVE-2009-2456 affects Novell eDirectory versions 8.8 up to SP4.
5
What is the impact of CVE-2009-2456 on system availability?
CVE-2009-2456 can lead to a core dump of the ndsd process, resulting in system downtime.