CVE-2009-2457: Code Injection
Published Jul 14, 2009
·Updated
The DS\NDSD component in Novell eDirectory 8.8 before SP5 allows remote attackers to cause a denial of service (crash) via a malformed bind LDAP packet.
Affected Software
6 affected components
Novell eDirectory=8.8
Novell eDirectory=8.8-sp3
Novell eDirectory=8.8-sp1
Novell eDirectory=8.8-sp4
Novell eDirectory=8.8-sp3
Novell eDirectory=8.8-sp2
Remediation
Patch Available
Event History
Jul 14, 2009
CVE Published
via MITRE·08:16 PM
Data Sourced
via MITRE·08:16 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-2457?
CVE-2009-2457 is classified as a high severity denial of service vulnerability.
2
How do I fix CVE-2009-2457?
To fix CVE-2009-2457, upgrade Novell eDirectory to version 8.8 SP5 or later.
3
What component is affected by CVE-2009-2457?
CVE-2009-2457 affects the DS/NDSD component in Novell eDirectory.
4
What attack vector is associated with CVE-2009-2457?
CVE-2009-2457 can be exploited by remote attackers via a malformed bind LDAP packet.
5
What versions of Novell eDirectory are vulnerable to CVE-2009-2457?
Novell eDirectory versions 8.8 before SP5, including SP1 to SP4, are vulnerable to CVE-2009-2457.