Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2008-0924

Quick assessment

Affected
n/a n/a
Exploitation
High exploitation probability; assess promptly
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Novell eDirectory是一个的跨平台的目录服务器。 Novell eDirectory处理畸形的请求数据时存在缓冲区溢出漏洞。如果向Novell eDirectory服务器发送了超长的LDAP扩展请求消息的话,就可能触发栈溢出,导致执行任意命令。

AI Predicted 10.0 Difficulty: Trivial EPSS 5.00% · P92
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2008-0924

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
Stack-based buffer overflow in the DoLBURPRequest function in libnldap in ndsd in Novell eDirectory 8.7.3.9 and earlier, and 8.8.1 and earlier in the 8.8.x series, allows remote attackers to cause a denial of service (daemon crash or CPU consumption) or execute arbitrary code via a long delRequest LDAP Extended Request message, probably involving a long Distinguished Name (DN) field.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Novell eDirectory LDAP扩展请求消息缓冲区溢出漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Novell eDirectory是一个的跨平台的目录服务器。 Novell eDirectory处理畸形的请求数据时存在缓冲区溢出漏洞。如果向Novell eDirectory服务器发送了超长的LDAP扩展请求消息的话,就可能触发栈溢出,导致执行任意命令。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2008-0924

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2008-0924

登录查看更多情报信息。

Vendor Advisories for CVE-2008-0924 (6)

Other References for CVE-2008-0924 (1)

Same Patch Batch · n/a · 2008-03-28 · 20 CVEs total

CVE-2008-1535 Joomla! Matti Kiviharju rekry 'op_id'参数 SQL注入漏洞
CVE-2008-1533 Joomla! 'XML-RPC Blogger API plugin'未明漏洞
CVE-2008-1532 Perlbal 缓冲区零字节上传远程拒绝服务漏洞
CVE-2008-1240 Mozilla Firefox/Thunderbird/SeaMonkey jar:协议处理错误漏洞
CVE-2008-1541 HIS WebShop 'his-webshop.pl' 目录遍历漏洞
CVE-2008-1540 Joomla! Mambo Datsogallery模块 'id' 参数 SQL注入漏洞
CVE-2008-1539 PHP-Nuke Platinum 'dynamic_titles.php' SQL注入漏洞
CVE-2008-1538 ManageEngine EventLog Analyzer 跨站脚本攻击漏洞
CVE-2008-1537 PowerBook '/index.php' 目录遍历漏洞
CVE-2008-1536 PICTURESPRO Photo Cart 'index.php' 跨站脚本攻击漏洞
CVE-2005-4874 Mozilla 代码注入漏洞
CVE-2008-1534 PowerPHPBoard 'settings[]'参数多个目录遍历漏洞
CVE-2008-0926 Novell eDirectory eMBox工具edirutil命令绕过认证漏洞
CVE-2008-1546 Mitsubishi Electric GB-50A Java applet远程绕过认证漏洞
CVE-2008-1545 Microsoft Internet Explorer安全漏洞
CVE-2008-1544 Microsoft IE 7 setRequestHeader()函数请求拆分漏洞
CVE-2008-1543 Airspan WiMAX ProST ProST web管理组件 信任管理漏洞
CVE-2008-1542 Airspan Base Station Distribution Unit 信任管理问题漏洞
CVE-2008-0704 HP TCP/IP Services for OpenVMS SSH 未明远程未授权访问漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2008-0924

No comments yet


Leave a comment