CVE-2006-4520
iDEFENSE Security Advisory 2007-04-26.1
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
ncp in Novell eDirectory before 8.7.3 SP9, and 8.8.x before 8.8.1 FTF2, does not properly handle NCP fragments with a negative length, which allows remote attackers to cause a denial of service (daemon crash) when the heap is written to a log file.
ncp en Novell eDirectory anterior a 8.7.3 SP9, y 8.8.x anterior a 8.8.1 FTF2, no maneja adecuadamente fragmentos NCP con una longitud negativa, lo cual permite a atacantes remotos provocar una denegación de servicio (caída del demonio) cuando el montón se escribe a un fichero de registro de eventos.
Remote exploitation of a denial of service (DoS) vulnerability in Novell Inc.'s eDirectory product could allow an attacker to force the running daemon to cease servicing requests. The problem specifically exists within the NCP functionality of eDirectory. Sending a sequence of specially crafted fragmented requests will cause a DoS condition. iDefense has confirmed the existence of this vulnerability in version 8.8.1 of Novell Inc.'s eDirectory server with FTF1 applied. The earliest version tested was 8.8. Earlier versions are suspected to be vulnerable.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2006-08-31 CVE Reserved
- 2007-04-30 CVE Published
- 2024-08-07 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/23685 | Vdb Entry | |
http://www.securitytracker.com/id?1017972 | Vdb Entry | |
http://www.vupen.com/english/advisories/2007/1550 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/33921 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.novell.com/support/search.do?cmd=displayKC&docType=kc&externalId=3924657&sliceId=SAL_Public | 2017-07-20 |
URL | Date | SRC |
---|---|---|
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=518 | 2017-07-20 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Novell Search vendor "Novell" | Edirectory Search vendor "Novell" for product "Edirectory" | <= 8.7.3.8 Search vendor "Novell" for product "Edirectory" and version " <= 8.7.3.8" | - |
Affected
| ||||||
Novell Search vendor "Novell" | Edirectory Search vendor "Novell" for product "Edirectory" | 8.8 Search vendor "Novell" for product "Edirectory" and version "8.8" | - |
Affected
| ||||||
Novell Search vendor "Novell" | Edirectory Search vendor "Novell" for product "Edirectory" | 8.8.1 Search vendor "Novell" for product "Edirectory" and version "8.8.1" | - |
Affected
|