| Vulnerability Name: | CVE-2009-3862 (CCN-54088) | ||||||||
| Assigned: | 2009-11-02 | ||||||||
| Published: | 2009-11-02 | ||||||||
| Updated: | 2009-11-05 | ||||||||
| Summary: | The NDSD process in Novell eDirectory 8.7.3 before 8.7.3.10 ftf2 and eDirectory 8.8 before 8.8.5 ftf1 does not properly handle certain LDAP search requests, which allows remote attackers to cause a denial of service (application hang) via a search request with a NULL BaseDN value. Per: http://www.novell.com/support/viewContent.do?externalId=7004721 "Resolution This vulnerability is resolved in eDirectory 8.8.5 ftf1 and eDirectory 8.7.3.10 ftf2. To resolve this problem, apply eDirectory 8.8.5 ftf1 or newer for eDirectory 8.8.X and eDirectory 8.7.3.10 ftf2 for eDirectory 8.7.3.X. Patches are available at http://download.novell.com" | ||||||||
| CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||||
| CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-287 | ||||||||
| Vulnerability Consequences: | Denial of Service | ||||||||
| References: | Source: MITRE Type: CNA CVE-2009-3862 Source: CCN Type: Novell Document ID: 7004721 Security Vulnerability: eDirectory LDAP Null Base DN Denial of Service Source: CONFIRM Type: Patch, Vendor Advisory http://www.novell.com/support/viewContent.do?externalId=7004721 Source: CCN Type: OSVDB ID: 59722 Novell eDirectory NDSD LDAP Search Request Remote DoS Source: BID Type: UNKNOWN 36902 Source: CCN Type: BID-36902 Novell eDirectory NULL Base DN Denial Of Service Vulnerability Source: VUPEN Type: Patch, Vendor Advisory ADV-2009-3120 Source: MISC Type: Patch http://www.zerodayinitiative.com/advisories/ZDI-09-075/ Source: XF Type: UNKNOWN novell-edirectory-ldap-dos(54088) Source: CCN Type: ZDI-09-075 Novell eDirectory LDAP Null Base DN Denial of Service Vulnerability | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||