Integer overflow in Novell eDirectory 8.7.3.x before 8.7.3.10 ftf2 and 8.8.x before 8.8.5.2 allows remote attackers to execute arbitrary code via an NDS Verb 0x1 request containing a large integer value that triggers a heap-based buffer overflow.
| Software | From | Fixed in |
|---|---|---|
| novell / edirectory | 8.7.3.9 | 8.7.3.9.x |
| novell / edirectory | 8.7.3-sp10 | 8.7.3-sp10.x |
| novell / edirectory | 8.7.3-sp4 | 8.7.3-sp4.x |
| novell / edirectory | 8.8.5 | 8.8.5.x |
| novell / edirectory | 8.8 | 8.8.x |
| novell / edirectory | 8.7.3 | 8.7.3.x |
| novell / edirectory | 8.8-sp1 | 8.8-sp1.x |
| novell / edirectory | 8.8-sp4 | 8.8-sp4.x |
| novell / edirectory | 8.7.3.10 | 8.7.3.10.x |
| novell / edirectory | 8.8.2 | 8.8.2.x |
| novell / edirectory | 8.8-sp3 | 8.8-sp3.x |
| novell / edirectory | 8.7.3-sp10_b | 8.7.3-sp10_b.x |
| novell / edirectory | 8.7.3-sp3 | 8.7.3-sp3.x |
| novell / edirectory | 8.7.3-sp5 | 8.7.3-sp5.x |
| novell / edirectory | 8.7.3.8 | 8.7.3.8.x |
| novell / edirectory | 8.8.1 | 8.8.1.x |
| novell / edirectory | 8.8-sp2 | 8.8-sp2.x |