icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons_061

eDirectory < 8.8.5.2/8.7.3.10 ftf2 'NDS Verb 0x1' Buffer Overflow

High

Synopsis

The remote host is vulnerable to a remote command execution attack.

Description

The remote host is running eDirectory, a directory service from Novell. The installed version is earlier than 8.8 SP5 ftf2, or 8.7.3.10 ftf2. Such versions are potentially affected by a remote buffer overflow vulnerability when handling specially crafted 'NDS Verb 0x1' requests. An attacker, exploiting this flaw, could execute arbitrary commands on the host subject to the privileges of the affected software.

Solution

Upgrade to eDirectory 8.8 SP5 ftf2 / 8.7.3.10 ftf2 or later.