Lucene search

K
cve[email protected]CVE-2008-5092
HistoryNov 14, 2008 - 7:20 p.m.

CVE-2008-5092

2008-11-1419:20:54
CWE-119
web.nvd.nist.gov
22
cve-2008-5092
novell edirectory
buffer overflow
http protocol
security vulnerability

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

6.3 Medium

AI Score

Confidence

Low

0.005 Low

EPSS

Percentile

75.7%

Heap-based buffer overflows in Novell eDirectory HTTP protocol stack (HTTPSTK) before 8.8 SP3 have unknown impact and attack vectors related to the (1) HTTP language header and (2) HTTP content-length header.

Affected configurations

NVD
Node
novelledirectoryRange8.8sp2windows
OR
novelledirectoryMatch8.0
OR
novelledirectoryMatch8.5
OR
novelledirectoryMatch8.5.12a
OR
novelledirectoryMatch8.5.27
OR
novelledirectoryMatch8.6.2
OR
novelledirectoryMatch8.7
OR
novelledirectoryMatch8.7.1
OR
novelledirectoryMatch8.7.1sp1
OR
novelledirectoryMatch8.7.3
OR
novelledirectoryMatch8.7.3sp1windows
OR
novelledirectoryMatch8.7.3sp2windows
OR
novelledirectoryMatch8.7.3sp3windows
OR
novelledirectoryMatch8.7.3sp4windows
OR
novelledirectoryMatch8.7.3sp5windows
OR
novelledirectoryMatch8.7.3sp6windows
OR
novelledirectoryMatch8.7.3sp7windows
OR
novelledirectoryMatch8.7.3sp8windows
OR
novelledirectoryMatch8.7.3sp9windows
OR
novelledirectoryMatch8.7.3.8
OR
novelledirectoryMatch8.7.3.8_presp9
OR
novelledirectoryMatch8.7.3.9
OR
novelledirectoryMatch8.7.3.9linux
OR
novelledirectoryMatch8.7.3.9solaris
OR
novelledirectoryMatch8.7.3.9windows_2000
OR
novelledirectoryMatch8.7.3.9windows_2003
OR
novelledirectoryMatch8.7.3.10
OR
novelledirectoryMatch8.8
OR
novelledirectoryMatch8.8linux
OR
novelledirectoryMatch8.8solaris
OR
novelledirectoryMatch8.8windows_2000
OR
novelledirectoryMatch8.8windows_2003
OR
novelledirectoryMatch8.8.1
OR
novelledirectoryMatch8.8.1linux
OR
novelledirectoryMatch8.8.1solaris
OR
novelledirectoryMatch8.8.1windows_2000
OR
novelledirectoryMatch8.8.1windows_2003
OR
novelledirectoryMatch8.8.2
OR
novelledirectoryMatch8.8.2linux
OR
novelledirectoryMatch8.8.2solaris
OR
novelledirectoryMatch8.8.2windows_2000
OR
novelledirectoryMatch8.8.2windows_2003
OR
novelledirectoryMatch85.20

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

6.3 Medium

AI Score

Confidence

Low

0.005 Low

EPSS

Percentile

75.7%

Related for CVE-2008-5092