Novell iManager eDirectory Plugin Schema Buffer Overflow
| TSL ID | FSC20100107-08 |
| CVE ID(s) | CVE-2009-4486 |
| Severity | High |
| Description | A code execution vulnerability has been reported in the Novell iManager eDirectory plugin. The vulnerability is due to improper input validation of an argument's length by a sub-application. This user-supplied data is copied into a statically allocated stack buffer. A remote, unauthenticated attacker can exploit this vulnerability by sending specially crafted parameters to the application in question. This can result in code execution within the privileges of the application. The vendor has released a patch regarding this vulnerability. It can be found at: http://www.novell.com/support/viewContent.do?externalId=7004985&sliceId=1 |
| Affected Products |
|
| CVSS Score |
Base 9.1 (AV:N/AC:L/Au:S/C:C/I:C/A:C):
|