CVE-2009-4486: Buffer Overflow
Published Jan 8, 2010
·Updated
Stack-based buffer overflow in the eDirectory plugin in Novell iManager before 2.7.3 allows remote attackers to execute arbitrary code via vectors that trigger long arguments to an unspecified sub-application, related to importing and exporting from a schema.
Affected Software
7 affected components
Novell iManager<=2.7.2
Novell iManager=1.5
Novell iManager=2.0
Novell iManager=2.0.2
Novell iManager=2.5
Novell iManager=2.6.0
Novell iManager=2.7.1
Remediation
Patch Available
Event History
Jan 8, 2010
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-4486?
CVE-2009-4486 is classified as a critical vulnerability due to its potential to allow remote code execution.
2
How do I fix CVE-2009-4486?
To fix CVE-2009-4486, update your Novell iManager to version 2.7.3 or later, which addresses this vulnerability.
3
What versions of Novell iManager are affected by CVE-2009-4486?
CVE-2009-4486 affects Novell iManager versions 1.5 to 2.7.2.
4
Can CVE-2009-4486 be exploited remotely?
Yes, CVE-2009-4486 can be exploited remotely by attackers without authentication.
5
What type of vulnerability is CVE-2009-4486?
CVE-2009-4486 is a stack-based buffer overflow vulnerability.