Preemptive Protection against Novell eDirectory Server iMonitor Vulnerability
| Attack ID: | CPAI-2005-116 |
| Publish Date: | |
| Last Update: | |
| Category: | Remote Code Execution |
| Vulnerable Systems: | Novell eDirectory 8.7.3 for Windows 2000, Windows NT and Windows 2003 |
| Source: |
Novell TID10098568 |
| Description: | Novell eDirectory is a Lightweight Directory Access Protocol (LDAP) directory-based identity management system that centralizes the management of user identities, access privileges and many other network resources. A buffer overflow vulnerability exists in Novell eDirectory Server iMonitor. An unauthenticated remote attacker can exploit the vulnerability to cause denial of service, or execute arbitrary code on the target system. |
| Severity: | |
| Details: | The vulnerability is caused by improper boundary checking when processing HTTP requests. A remote attacker can trigger the vulnerability by requesting a resource with an overly long name in the "nds/" folder. |
| Attack Detection: | Users of VPN-1 NG with Application Intelligence R55W, users of VPN-1 NGX R60 and users of Connectra who have applied the solution outlined below will identify the attack by the following log produced by SmartView Tracker: Attack Name: Malicious Code Protector
|
| Solution: | Users of VPN-1 NG with Application Intelligence R55W, users of VPN-1 NGX R60 and users of Connectra can protect against this vulnerability using the Malicious Code Protector (MCP). |
| Industry Reference: |
CAN-2005-2551 |
| Additional Information: |
|