Title : Novell eDirectory LDAP Search Request Heap Corruption Vulnerability VUPEN ID : VUPEN/ADV-2008-2062 CVE ID : CVE-2008-1809 CWE ID : CWE-122
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-07-11
Technical Description
A vulnerability has been identified in Novell eDirectory, which could be exploited by remote attackers to cause a denial of service or potentially take complete control of an affected system. This issue is caused by an incorrect calculation when allocating a heap buffer to store the search parameters, which could be exploited by attackers to overflow a heap based buffer with the string "(null)" by passing NULL search parameters, which could cause the application to crash or potentially execute arbitrary code.