All Threats

Viruses

Hackers

Spam

Whole site    Viruses
  
About Hackers
Analysis
News
Glossary
Weblog



 
Virus Encyclopedia
Virus Encyclopedia

Learn about worms, viruses, Trojans and more in our Virus Encyclopedia.

About Spam
About Spam

Read about spam and spammers in our About Spam section.

 

  Home / Hackers / About Hackers / Software Vulnerabilities / Examples and Descriptions / SA38491

Novell eDirectory eMBox SOAP Request Vulnerability

Secunia ID

SA38491

CVE-ID

CVE-2010-0666

Release Date

09 Feb 2010

Last Change

03 Mar 2010

Criticality

Less Critical

Solution Status

Vendor Patch

Software

Novell eDirectory 8.x

Where

From local network

Impact
DoS (Denial of Service)

This includes vulnerabilities ranging from excessive resource consumption (e.g. causing a system to use a lot of memory) to crashing an application or an entire system.


Description

A vulnerability has been reported in Novell eDirectory, which can be exploited by malicious people to cause a DoS (Denial of Service).

The vulnerability is caused due to an unspecified error in eMBox, which can be exploited to cause eDirectory to crash via a specially crafted SOAP request.

The vulnerability is reported in versions prior to 8.8 SP5 Patch 3.

NOTE: An issue where SAdmin is allowed to login with a null password has also been reported by the vendor.

Solution

Update to eDirectory 8.8 SP5 Patch 3.

Reported by

1c239c43f521145fa8385d64a9c32243 reported via ZDI.

Original Advisory

Novell:
http://www.novell.com/support/viewContent.do?externalId=3426981
http://www.novell.com/support/viewContent.do?externalId=7005341

ZDI:
http://www.zerodayinitiative.com/advisories/ZDI-10-024/




 

Copyright © 1996 - 2010
Kaspersky Lab
Industry-leading Antivirus Software
All rights reserved
 

Email: webmaster@viruslist.com