Lucene search

K
cve[email protected]CVE-2009-3862
HistoryNov 04, 2009 - 6:30 p.m.

CVE-2009-3862

2009-11-0418:30:00
CWE-287
web.nvd.nist.gov
31
novell
edirectory
ldap
search request
dos
cve-2009-3862
nvd

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

6.6 Medium

AI Score

Confidence

High

0.024 Low

EPSS

Percentile

90.1%

The NDSD process in Novell eDirectory 8.7.3 before 8.7.3.10 ftf2 and eDirectory 8.8 before 8.8.5 ftf1 does not properly handle certain LDAP search requests, which allows remote attackers to cause a denial of service (application hang) via a search request with a NULL BaseDN value.

Affected configurations

NVD
Node
novelledirectoryMatch8.7.3
OR
novelledirectoryMatch8.7.3sp2windows
OR
novelledirectoryMatch8.7.3sp3windows
OR
novelledirectoryMatch8.7.3sp4windows
OR
novelledirectoryMatch8.7.3sp5windows
OR
novelledirectoryMatch8.7.3sp6windows
OR
novelledirectoryMatch8.7.3sp7windows
OR
novelledirectoryMatch8.7.3sp8windows
OR
novelledirectoryMatch8.7.3sp9windows
OR
novelledirectoryMatch8.7.3.8
OR
novelledirectoryMatch8.7.3.9
OR
novelledirectoryMatch8.8
OR
novelledirectoryMatch8.8sp1
OR
novelledirectoryMatch8.8sp2
OR
novelledirectoryMatch8.8sp3
OR
novelledirectoryMatch8.8sp4
OR
novelledirectoryMatch8.8.1
OR
novelledirectoryMatch8.8.2

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

6.6 Medium

AI Score

Confidence

High

0.024 Low

EPSS

Percentile

90.1%

Related for CVE-2009-3862