Novell patches eDirectory buffer overflow vulnerability

Article

Novell patches eDirectory buffer overflow vulnerability

Edmund X. DeJesus, Contributor

Waltham, Mass.-based Novell Inc. has issued a bulletin to remedy a moderately critical security vulnerability in eDirectory. Unless fixed, the unspecified vulnerability could be exploited by a local user to cause a

    Requires Free Membership to View

    SearchSecurity.co.UK members gain immediate and unlimited access to breaking UK industry news, virus alerts, new hacker threats, highly focused security newsletters, and more -- all at no cost. Join me on SearchSecurity.co.UK today!

    Michael S. Mimoso, Editorial Director

    By submitting your registration information to SearchSecurity.co.uk you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchSecurity.co.uk is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

denial of service and possible unauthorized system access in the target system.

Novell eDirectory is an LDAP directory service, used for identity-management deployments and multiplatform network services. The current flaw occurs in eDirectory's iMonitor component, which provides Web-based cross-platform monitoring and diagnostic capabilities.

The issue occurs because of the possibility of forcing a buffer overflow in an unspecified part of iMonitor processing, which could cause a denial of service. Because eDirectory is an LDAP directory service, a denial-of-service attack could cause more widespread security issues, including the possibility of unauthorized system access.

Version 2.4 of iMonitor, which ships with eDirectory version 8.8, is known to be vulnerable. Novell has provided a patch for this vulnerability on Windows, UNIX, and NetWare systems.

It is unclear whether the current vulnerability may be related to a security flaw in iMonitor previously reported by Danish vulnerability clearinghouse Secunia. In August 2005, another buffer overflow problem in iMonitor allowed execution of arbitrary code with system privileges. Again, unauthorized system access was a possible secondary effect of the vulnerability. Also in 2005, Novell reported unrelated eDirectory vulnerabilities with remote denial of service and the possibility of bypassing passwords.

Edmund X. DeJesus is a freelance writer in Norwood, Mass.