The NDSD process in Novell eDirectory 8.7.3 before 8.7.3.10 ftf2 and eDirectory 8.8 before 8.8.5 ftf1 does not properly handle certain LDAP search requests, which allows remote attackers to cause a denial of service (application hang) via a search request with a NULL BaseDN value.
| Software | From | Fixed in |
|---|---|---|
| novell / edirectory | 8.7.3.9 | 8.7.3.9.x |
| novell / edirectory | 8.7.3-sp5 | 8.7.3-sp5.x |
| novell / edirectory | 8.8 | 8.8.x |
| novell / edirectory | 8.8-sp3 | 8.8-sp3.x |
| novell / edirectory | 8.7.3 | 8.7.3.x |
| novell / edirectory | 8.7.3-sp4 | 8.7.3-sp4.x |
| novell / edirectory | 8.8-sp1 | 8.8-sp1.x |
| novell / edirectory | 8.8-sp4 | 8.8-sp4.x |
| novell / edirectory | 8.7.3-sp8 | 8.7.3-sp8.x |
| novell / edirectory | 8.8.2 | 8.8.2.x |
| novell / edirectory | 8.7.3-sp3 | 8.7.3-sp3.x |
| novell / edirectory | 8.7.3-sp6 | 8.7.3-sp6.x |
| novell / edirectory | 8.7.3-sp7 | 8.7.3-sp7.x |
| novell / edirectory | 8.7.3.8 | 8.7.3.8.x |
| novell / edirectory | 8.8.1 | 8.8.1.x |
| novell / edirectory | 8.7.3-sp2 | 8.7.3-sp2.x |
| novell / edirectory | 8.7.3-sp9 | 8.7.3-sp9.x |
| novell / edirectory | 8.8-sp2 | 8.8-sp2.x |