Novell eDirectory 'ds.dlm' Module Integer Overflow Vulnerability

Novell eDirectory is prone to a vulnerability in the 'ds.dlm' module. The software fails to adequately bounds-check user-supplied data, resulting in an integer-overflow condition.

An attacker can exploit this vulnerability to execute arbitrary code in the context of the eDirectory process. Failed exploit attempts will likely cause denial-of-service conditions.

This issue affects Novell eDirectory 8.7.3 and 8.8 for all platforms.


 

Privacy Statement
Copyright 2010, SecurityFocus