>> Novell eDirectory "BerDecodeLoginDataRequest()" Denial Of Service Vulnerability
Title : Novell eDirectory "BerDecodeLoginDataRequest()" Denial Of Service Vulnerability VUPEN ID : VUPEN/ADV-2006-4293 CVE ID : CVE-2006-4521
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-11-01
Technical Description
A vulnerability has been identified in Novell eDirectory, which could be exploited by remote attackers to cause a denial of service. This flaw is due to a NULL pointer dereference error in the "libnmasldap.so" module when processing malformed login requests via the "BerDecodeLoginDataRequest()" function, which could be exploited by attackers to crash a vulnerable server, creating a denial of service condition.