Release date:
Updated on:
Affected Systems:
Netiq eDirectory 8.8.7.x
Netiq eDirectory 8.8.6.x
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2012-0429
NetIQ eDirectory is an LDAP directory.
Security Vulnerabilities exist in NetIQ eDirectory 8.8.6.x and 8.8.7.x. If some special characters are contained in verified http requests, dhost crashes. Malicious attackers can exploit this vulnerability to launch DoS attacks.
<* Source: Positive Research
Link: http://www.novell.com/support/kb/doc.php? Id = 7011533
Http://www.novell.com/support/kb/doc.php? Id = 3426981
Http://web.nvd.nist.gov/view/vuln/detail? VulnId = CVE-2012-0429
Http://www.novell.com/support/kb/doc.php? Id = 7011538
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Netiq
-----
Netiq has released a Security Bulletin (7011538) and corresponding patches for this purpose:
7011538: Security Vulnerability: eDirectory Authorization mechanic Bypass
Link: http://www.novell.com/support/kb/doc.php? Id = 7011538
Patch download:
Http://download.novell.com/