CVE-2009-4654: Buffer Overflow
Published Feb 26, 2010
·Updated
Stack-based buffer overflow in the dhost module in Novell eDirectory 8.8 SP5 for Windows allows remote authenticated users to execute arbitrary code via long sadminpwd and verifypwd parameters in a submit action to /dhost/httpstk.
Affected Software
4 affected components
Novell eDirectory=8.8-sp5
Microsoft Windows
All of the following
Novell eDirectory=8.8-sp5
Microsoft Windows
Event History
Feb 26, 2010
CVE Published
via MITRE·06:09 PM
Data Sourced
via MITRE·06:09 PM
Description
Data Sourced
06:30 PM
DescriptionWeaknessAffected Software
Data Sourced
via NVD·06:30 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-4654?
CVE-2009-4654 is rated as a high severity vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2009-4654?
To mitigate CVE-2009-4654, update Novell eDirectory to a later version that addresses this vulnerability.
3
What systems are affected by CVE-2009-4654?
CVE-2009-4654 specifically affects Novell eDirectory 8.8 SP5 on Windows.
4
Who can exploit CVE-2009-4654?
Remote authenticated users can exploit CVE-2009-4654 by sending specially crafted input to the application.
5
What are the consequences of CVE-2009-4654?
Exploitation of CVE-2009-4654 could allow attackers to execute arbitrary code on the affected system.