ID

VAR-201010-0436


TITLE

Novell eDirectory Server Malformed Index Denial of Service Vulnerability

Trust: 2.0

sources: IVD: 7d7e3d5f-463f-11e9-9625-000c29342cb1 // IVD: 9163851c-1fad-11e6-abef-000c29c66e3d // ZDI: ZDI-10-189 // CNVD: CNVD-2010-2237 // BID: 43662

DESCRIPTION

This vulnerability allows attackers to deny services on vulnerable installations of Novell eDirectory. Authentication is not required in order to trigger this vulnerability.The flaw exists within Novell's eDirectory Server's NCP implementation which binds, by default, to TCP port 524. While handling a malformed request, the application explicitly trusts a field when translating it to an index into a table of counters. If this index is too large, the application will set a value outside the array and the ndsd process will become unresponsive resulting in an inability to authenticate to that server. Novell eDirectory is a cross-platform directory server. Novell eDirectory is prone to a denial-of-service vulnerability. Remote attackers can exploit this issue to crash the application, denying service to legitimate users. Versions prior to eDirectory 8.8.5 ftf3 are vulnerable. ZDI-10-189: Novell eDirectory Server Malformed Index Denial of Service Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-189 October 1, 2010 -- CVSS: 7.8, (AV:N/AC:L/Au:N/C:N/I:N/A:C) -- Affected Vendors: Novell -- Affected Products: Novell eDirectory -- TippingPoint(TM) IPS Customer Protection: TippingPoint IPS customers have been protected against this vulnerability by Digital Vaccine protection filter ID 9971. -- Vendor Response: Novell has issued an update to correct this vulnerability. More details can be found at: http://www.novell.com/support/viewContent.do?externalId=7006389&sliceId=2 -- Disclosure Timeline: 2009-04-28 - Vulnerability reported to vendor 2010-10-01 - Coordinated public release of advisory -- Credit: This vulnerability was discovered by: * 1c239c43f521145fa8385d64a9c32243 -- About the Zero Day Initiative (ZDI): Established by TippingPoint, The Zero Day Initiative (ZDI) represents a best-of-breed model for rewarding security researchers for responsibly disclosing discovered vulnerabilities. Researchers interested in getting paid for their security research through the ZDI can find more information and sign-up at: http://www.zerodayinitiative.com The ZDI is unique in how the acquired vulnerability information is used. TippingPoint does not re-sell the vulnerability details or any exploit code. Instead, upon notifying the affected product vendor, TippingPoint provides its customers with zero day protection through its intrusion prevention technology. Explicit details regarding the specifics of the vulnerability are not exposed to any parties until an official vendor patch is publicly available. Furthermore, with the altruistic aim of helping to secure a broader user base, TippingPoint provides this vulnerability information confidentially to security vendors (including competitors) who have a vulnerability protection or mitigation product. Our vulnerability disclosure policy is available online at: http://www.zerodayinitiative.com/advisories/disclosure_policy/ Follow the ZDI on Twitter: http://twitter.com/thezdi _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Trust: 1.89

sources: ZDI: ZDI-10-189 // CNVD: CNVD-2010-2237 // BID: 43662 // IVD: 7d7e3d5f-463f-11e9-9625-000c29342cb1 // IVD: 9163851c-1fad-11e6-abef-000c29c66e3d // PACKETSTORM: 94434

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 1.0

sources: IVD: 7d7e3d5f-463f-11e9-9625-000c29342cb1 // IVD: 9163851c-1fad-11e6-abef-000c29c66e3d // CNVD: CNVD-2010-2237

AFFECTED PRODUCTS

vendor:novellmodel:edirectoryscope: - version: -

Trust: 0.7

vendor:novellmodel:edirectory ftf1/8.8.2 ftf2/8.8.2/8.8.1/8.8.5.2/8.8 sp5 ftf1/8.8 sp5/8.8 sp4 ftf1/8.8 sp4/8.8 sp3 ftf3/8.8 sp3/8.8 sp2/8.8 sp1/8.8scope:eqversion:8.8.5

Trust: 0.6

vendor:novellmodel:edirectory ftf1/8.8.2 ftf2/8.8.2/8.8.1/8.8.5.2/8.8 sp5 ftf1/8.8 sp5/8.8 sp4 ftf1/8.8 sp4/8.8 sp3 ftf3/8.8 sp3/8.8 sp2/8.8 sp1/8.8scope:eqversion:8.8.5*

Trust: 0.4

vendor:novellmodel:edirectory ftf1scope:eqversion:8.8.5

Trust: 0.3

vendor:novellmodel:edirectory ftf2scope:eqversion:8.8.2

Trust: 0.3

vendor:novellmodel:edirectoryscope:eqversion:8.8.2

Trust: 0.3

vendor:novellmodel:edirectoryscope:eqversion:8.8.1

Trust: 0.3

vendor:novellmodel:edirectoryscope:eqversion:8.8.5.2

Trust: 0.3

vendor:novellmodel:edirectory sp5 ftf1scope:eqversion:8.8

Trust: 0.3

vendor:novellmodel:edirectory sp5scope:eqversion:8.8

Trust: 0.3

vendor:novellmodel:edirectory sp4 ftf1scope:eqversion:8.8

Trust: 0.3

vendor:novellmodel:edirectory sp4scope:eqversion:8.8

Trust: 0.3

vendor:novellmodel:edirectory sp3 ftf3scope:eqversion:8.8

Trust: 0.3

vendor:novellmodel:edirectory sp3scope:eqversion:8.8

Trust: 0.3

vendor:novellmodel:edirectory sp2scope:eqversion:8.8

Trust: 0.3

vendor:novellmodel:edirectory sp1scope:eqversion:8.8

Trust: 0.3

vendor:novellmodel:edirectoryscope:eqversion:8.8

Trust: 0.3

vendor:novellmodel:edirectory ftf3scope:neversion:8.8.5

Trust: 0.3

sources: IVD: 7d7e3d5f-463f-11e9-9625-000c29342cb1 // IVD: 9163851c-1fad-11e6-abef-000c29c66e3d // ZDI: ZDI-10-189 // CNVD: CNVD-2010-2237 // BID: 43662

CVSS

SEVERITY

CVSSV2

CVSSV3

ZDI: ZDI-10-189
value: HIGH

Trust: 0.7

IVD: 7d7e3d5f-463f-11e9-9625-000c29342cb1
value: HIGH

Trust: 0.2

IVD: 9163851c-1fad-11e6-abef-000c29c66e3d
value: LOW

Trust: 0.2

ZDI: ZDI-10-189
severity: HIGH
baseScore: 7.8
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.7

IVD: 7d7e3d5f-463f-11e9-9625-000c29342cb1
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

IVD: 9163851c-1fad-11e6-abef-000c29c66e3d
severity: NONE
baseScore: NONE
vectorString: NONE
accessVector: NONE
accessComplexity: NONE
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: UNKNOWN

Trust: 0.2

sources: IVD: 7d7e3d5f-463f-11e9-9625-000c29342cb1 // IVD: 9163851c-1fad-11e6-abef-000c29c66e3d // ZDI: ZDI-10-189

THREAT TYPE

network

Trust: 0.3

sources: BID: 43662

TYPE

Unknown

Trust: 0.3

sources: BID: 43662

PATCH

title:Novell has issued an update to correct this vulnerability.url:http://www.novell.com/support/viewcontent.do?externalid=7006389&sliceid=2

Trust: 0.7

title:Novell eDirectory Server malformation index denial of service vulnerability patchurl:https://www.cnvd.org.cn/patchinfo/show/1200

Trust: 0.6

sources: ZDI: ZDI-10-189 // CNVD: CNVD-2010-2237

EXTERNAL IDS

db:ZDIid:ZDI-10-189

Trust: 1.7

db:CNVDid:CNVD-2010-2237

Trust: 1.0

db:BIDid:43662

Trust: 0.9

db:ZDI_CANid:ZDI-CAN-477

Trust: 0.7

db:IVDid:7D7E3D5F-463F-11E9-9625-000C29342CB1

Trust: 0.2

db:IVDid:9163851C-1FAD-11E6-ABEF-000C29C66E3D

Trust: 0.2

db:PACKETSTORMid:94434

Trust: 0.1

sources: IVD: 7d7e3d5f-463f-11e9-9625-000c29342cb1 // IVD: 9163851c-1fad-11e6-abef-000c29c66e3d // ZDI: ZDI-10-189 // CNVD: CNVD-2010-2237 // BID: 43662 // PACKETSTORM: 94434

REFERENCES

url:http://www.novell.com/support/viewcontent.do?externalid=7006389&sliceid=2

Trust: 1.0

url:http://www.zerodayinitiative.com/advisories/zdi-10-189

Trust: 1.0

url:http://www.novell.com

Trust: 0.3

url:http://www.zerodayinitiative.com/advisories/disclosure_policy/

Trust: 0.1

url:http://secunia.com/

Trust: 0.1

url:http://twitter.com/thezdi

Trust: 0.1

url:http://www.tippingpoint.com

Trust: 0.1

url:http://www.novell.com/support/viewcontent.do?externalid=7006389&sliceid=2

Trust: 0.1

url:http://www.zerodayinitiative.com

Trust: 0.1

url:http://lists.grok.org.uk/full-disclosure-charter.html

Trust: 0.1

sources: ZDI: ZDI-10-189 // CNVD: CNVD-2010-2237 // BID: 43662 // PACKETSTORM: 94434

CREDITS

1c239c43f521145fa8385d64a9c32243

Trust: 0.7

sources: ZDI: ZDI-10-189

SOURCES

db:IVDid:7d7e3d5f-463f-11e9-9625-000c29342cb1
db:IVDid:9163851c-1fad-11e6-abef-000c29c66e3d
db:ZDIid:ZDI-10-189
db:CNVDid:CNVD-2010-2237
db:BIDid:43662
db:PACKETSTORMid:94434

LAST UPDATE DATE

2022-05-17T02:01:24.186000+00:00


SOURCES UPDATE DATE

db:ZDIid:ZDI-10-189date:2010-10-01T00:00:00
db:CNVDid:CNVD-2010-2237date:2010-10-03T00:00:00
db:BIDid:43662date:2010-10-01T00:00:00

SOURCES RELEASE DATE

db:IVDid:7d7e3d5f-463f-11e9-9625-000c29342cb1date:2010-10-03T00:00:00
db:IVDid:9163851c-1fad-11e6-abef-000c29c66e3ddate:2010-10-03T00:00:00
db:ZDIid:ZDI-10-189date:2010-10-01T00:00:00
db:CNVDid:CNVD-2010-2237date:2010-10-03T00:00:00
db:BIDid:43662date:2010-10-01T00:00:00
db:PACKETSTORMid:94434date:2010-10-01T22:21:45