Home→Descriptions→SA38491
| Secunia ID | |
| CVE-ID | |
| Release Date |
09 Feb 2010 |
| Last Change |
03 Mar 2010 |
| Criticality | |
| Solution Status |
Vendor Patch |
| Software |
Novell eDirectory 8.x |
| Where | |
| Impact |
DoS (Denial of Service)This includes vulnerabilities ranging from excessive resource consumption (e.g. causing a system to use a lot of memory) to crashing an application or an entire system. |
| Description |
A vulnerability has been reported in Novell eDirectory, which can be exploited by malicious people to cause a DoS (Denial of Service). The vulnerability is caused due to an unspecified error in eMBox, which can be exploited to cause eDirectory to crash via a specially crafted SOAP request. The vulnerability is reported in versions prior to 8.8 SP5 Patch 3. NOTE: An issue where SAdmin is allowed to login with a null password has also been reported by the vendor. |
| Solution |
Update to eDirectory 8.8 SP5 Patch 3. |
| Reported by |
1c239c43f521145fa8385d64a9c32243 reported via ZDI. |
| Original Advisory |
Novell: |