| Vulnerability Name: | CVE-2008-3159 (CCN-43589) | ||||||||
| Assigned: | 2008-07-02 | ||||||||
| Published: | 2008-07-02 | ||||||||
| Updated: | 2017-08-08 | ||||||||
| Summary: | Integer overflow in ds.dlm, as used by dhost.exe, in Novell eDirectory 8.7.3.10 before 8.7.3 SP10b and 8.8 before 8.8.2 ftf2 allows remote attackers to execute arbitrary code via unspecified vectors that trigger a stack-based buffer overflow, related to "flawed arithmetic." | ||||||||
| CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
| CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C) 7.4 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
5.5 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-189 | ||||||||
| Vulnerability Consequences: | Gain Access | ||||||||
| References: | Source: MITRE Type: CNA CVE-2008-3159 Source: CCN Type: SA30938 Novell eDirectory ds.dlm Module Buffer Overflow Source: SECUNIA Type: Vendor Advisory 30938 Source: CCN Type: SECTRACK ID: 1020431 Novell eDirectory Integer Overflow in 'ds.dlm' Lets Remote Users Execute Arbitrary Code Source: SECTRACK Type: UNKNOWN 1020431 Source: CCN Type: Novell Web site eDirectory Source: CONFIRM Type: UNKNOWN http://www.novell.com/support/search.do?cmd=displayKC&sliceId=SAL_Public&externalId=3694858 Source: CCN Type: Novell Security Alert Document ID: 3694858 Security Vulnerability: Integer overflow stack corruption Source: CCN Type: OSVDB ID: 46708 Novell eDirectory ds.dlm Crafted Packet Handling Remote Overflow Source: BID Type: UNKNOWN 30085 Source: CCN Type: BID-30085 Novell eDirectory 'ds.dlm' Module Integer Overflow Vulnerability Source: VUPEN Type: UNKNOWN ADV-2008-1999 Source: MISC Type: UNKNOWN http://www.zerodayinitiative.com/advisories/ZDI-08-041/ Source: XF Type: UNKNOWN novell-edirectory-dsdlm-bo(43589) Source: XF Type: UNKNOWN novell-edirectory-dsdlm-bo(43589) Source: CCN Type: ZDI-08-041 Novell eDirectory dhost Integer Overflow Code Execution Vulnerability | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||