First published: Wed Nov 04 2009(Updated: )
The NDSD process in Novell eDirectory 8.7.3 before 8.7.3.10 ftf2 and eDirectory 8.8 before 8.8.5 ftf1 does not properly handle certain LDAP search requests, which allows remote attackers to cause a denial of service (application hang) via a search request with a NULL BaseDN value.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microfocus eDirectory | =8.7.3.9 | |
Microfocus eDirectory | =8.7.3-sp5 | |
Microfocus eDirectory | =8.8 | |
Microfocus eDirectory | =8.8-sp3 | |
Microfocus eDirectory | =8.7.3 | |
Microfocus eDirectory | =8.7.3-sp4 | |
Microfocus eDirectory | =8.8-sp1 | |
Microfocus eDirectory | =8.8-sp4 | |
Microfocus eDirectory | =8.7.3-sp8 | |
Microfocus eDirectory | =8.8.2 | |
Microfocus eDirectory | =8.7.3-sp3 | |
Microfocus eDirectory | =8.7.3-sp6 | |
Microfocus eDirectory | =8.7.3-sp7 | |
Microfocus eDirectory | =8.7.3.8 | |
Microfocus eDirectory | =8.8.1 | |
Microfocus eDirectory | =8.7.3-sp2 | |
Microfocus eDirectory | =8.7.3-sp9 | |
Microfocus eDirectory | =8.8-sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-3862 has a severity rating that indicates it can lead to a denial of service by causing the application to hang.
To fix CVE-2009-3862, upgrade to Novell eDirectory versions 8.7.3.10 ftf2 or 8.8.5 ftf1 or later.
CVE-2009-3862 affects Novell eDirectory versions 8.7.3 before 8.7.3.10 ftf2 and 8.8 before 8.8.5 ftf1.
Yes, an attacker can exploit CVE-2009-3862 remotely by sending a specially crafted LDAP search request with a NULL BaseDN value.
The impact of CVE-2009-3862 on Novell eDirectory is an application hang, resulting in denial of service.