RULE(RULE ID:2105108)

Rule General Information
Release Date: 2020-08-04
Rule Name: Novell eDirectory LDAP NULL Search Parameter Buffer Overflow Vulnerability (CVE-2008-1809)
Severity:
CVE ID:
Rule Protection Details
Description: Heap-based buffer overflow in Novell eDirectory 8.7.3 before 8.7.3.10b, and 8.8 before 8.8.2 FTF2, allows remote attackers to execute arbitrary code via an LDAP search request containing "NULL search parameters."
Impact: A buffer overflow vulnerability can be triggered by an attacker in the context of the vulnerable product. Further attacks includes arbitrary code execution and denial of service.
Affected OS: Linux
Reference: SecurityFocusBID:30175
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=724
http://www.novell.com/support/viewContent.do?externalId=3843876
SecurityTrackerID:1020470
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
http://download.novell.com/