CVE-2006-5478
published 2006-10-24CVE-2006-5478: Multiple stack-based buffer overflows in Novell eDirectory 8.8.x before 8.8.1 FTF1, and 8.x up to 8.7.3.8, and Novell NetMail before 3.52e FTF2, allow remote…
PriorityP270high7.5CVSS 2.0
AVNACLAuNCPIPAP
EXPLOIT
EPSS
83.89%
99.7th percentile
Multiple stack-based buffer overflows in Novell eDirectory 8.8.x before 8.8.1 FTF1, and 8.x up to 8.7.3.8, and Novell NetMail before 3.52e FTF2, allow remote attackers to execute arbitrary code via (1) a long HTTP Host header, which triggers an overflow in the BuildRedirectURL function; or vectors related to a username containing a . (dot) character in the (2) SMTP, (3) POP, (4) IMAP, (5) HTTP, or (6) Networked Messaging Application Protocol (NMAP) Netmail services.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| novell | edirectory | — | — |
| novell | edirectory | — | — |
| novell | edirectory | — | — |
| novell | edirectory | — | — |
| novell | edirectory | — | — |
| novell | edirectory | — | — |
| novell | edirectory | — | — |
| novell | edirectory | — | — |
| novell | edirectory | — | — |
Detection & IOCsextracted from sources · hover to see the quote
bytes↗
\x81\xc4\x54\xf2\xff\xff
bytes↗
\xde\xc0\xad\xde
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
Novell eDirectory NDS Server - Host Header Overflow (Metasploit)
exploitdb·2010-05-09
CVE-2006-5478 Novell eDirectory NDS Server - Host Header Overflow (Metasploit)
Novell eDirectory NDS Server - Host Header Overflow (Metasploit)
---
##
# $Id: edirectory_host.rb 9262 2010-05-09 17:45:00Z jduck $
##
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# Framework web site for more information on licensing and terms of use.
# http://metasploit.com/framework/
##
require 'msf/core'
class Metasploit3 'Novell eDirectory NDS Server Host Header Overflow',
'Description' => %q{
This module exploits a stack buffer overflow in Novell eDirectory 8.8.1.
The web interface does not validate the length of the
HTTP Host header prior to using the value of that header in an
HTTP redirect.
},
'Author' => 'MC',
'License' => MSF_LICENSE,
'Version' => '$Revision: 9262 $',
'Refere
Exploit-DB
Novell eDirectory 8.x - iMonitor HTTPSTK Buffer Overflow (3)
exploitdb·2006-10-30
CVE-2006-5478 Novell eDirectory 8.x - iMonitor HTTPSTK Buffer Overflow (3)
Novell eDirectory 8.x - iMonitor HTTPSTK Buffer Overflow (3)
---
source: https://www.securityfocus.com/bid/20655/info
The Novell eDirectory server iMonitor is prone to a stack-based buffer-overflow vulnerability because it fails to perform sufficient bounds checking on client-supplied data before copying it to a buffer.
An attacker could leverage this issue to execute arbitrary code with administrative privileges. A successful exploit could result in the complete compromise of the affected system.
##
# $Id$
##
##
# This file is part of the Metasploit Framework and may be subject to
# redistribution and commercial restrictions. Please see the Metasploit
# Framework web site for more information on licensing and terms of use.
# http://metasploit.com/framework/
##
require 'msf/core'
Exploit-DB
Novell eDirectory 8.x - iMonitor HTTPSTK Buffer Overflow (2)
exploitdb·2006-10-30
CVE-2006-5478 Novell eDirectory 8.x - iMonitor HTTPSTK Buffer Overflow (2)
Novell eDirectory 8.x - iMonitor HTTPSTK Buffer Overflow (2)
---
// source: https://www.securityfocus.com/bid/20655/info
The Novell eDirectory server iMonitor is prone to a stack-based buffer-overflow vulnerability because it fails to perform sufficient bounds checking on client-supplied data before copying it to a buffer.
An attacker could leverage this issue to execute arbitrary code with administrative privileges. A successful exploit could result in the complete compromise of the affected system.
/*
_______ ________ .__ _____ __
___ __\ _ \ ____ \_____ \ | |__ / | | ____ | | __
\ \/ / /_\ \ / \ _(__ __|_ \
\/ \/ \/ \/ 30\10\06 \/ |__| \/ \/
* mm. dM8
* YMMMb. dMM8 _____________________________________
* YMMMMb dMMM' [ ]
* `YMMMb dMMMP [ There are doors I have yet to open ]
* `YMM
Exploit-DB
Novell eDirectory 8.x - iMonitor HTTPSTK Buffer Overflow (1)
exploitdb·2006-10-21
CVE-2006-5478 Novell eDirectory 8.x - iMonitor HTTPSTK Buffer Overflow (1)
Novell eDirectory 8.x - iMonitor HTTPSTK Buffer Overflow (1)
---
source: https://www.securityfocus.com/bid/20655/info
The Novell eDirectory server iMonitor is prone to a stack-based buffer-overflow vulnerability because it fails to perform sufficient bounds checking on client-supplied data before copying it to a buffer.
An attacker could leverage this issue to execute arbitrary code with administrative privileges. A successful exploit could result in the complete compromise of the affected system.
#!perl
#
# "Novell eDirectory 8.8 NDS Server" Remote Stack Overflow Exploit
#
# Author: Manuel Santamarina Suarez
# e-Mail: [email protected]
#
use IO::Socket;
#
# destination IP address
#
$ip = '192.168.1.25';
#
# destination TCP port
#
$port = 8028;
#
# RETurn address. 0x00, 0x0a, 0x0d
Metasploit
Novell eDirectory NDS Server Host Header Overflow
metasploit
Novell eDirectory NDS Server Host Header Overflow
Novell eDirectory NDS Server Host Header Overflow
This module exploits a stack buffer overflow in Novell eDirectory 8.8.1. The web interface does not validate the length of the HTTP Host header prior to using the value of that header in an HTTP redirect.
No writeups or analysis indexed.
http://lists.grok.org.uk/pipermail/full-disclosure/2006-October/050382.htmlhttp://lists.grok.org.uk/pipermail/full-disclosure/2006-October/050388.htmlhttp://secunia.com/advisories/22519http://securitytracker.com/id?1017125http://securitytracker.com/id?1017141http://support.novell.com/cgi-bin/search/searchtid.cgi?/2974600.htmhttp://www.mnin.org/advisories/2006_novell_httpstk.pdfhttp://www.novell.com/support/search.do?cmd=displayKC&docType=kc&externalId=3723994&sliceId=SAL_Public&dialogID=16776123&stateId=1%200%202648401http://www.securityfocus.com/archive/1/449899/100/0/threadedhttp://www.securityfocus.com/archive/1/450017/100/0/threadedhttp://www.securityfocus.com/archive/1/450520/100/100/threadedhttp://www.securityfocus.com/bid/20655http://www.securityfocus.com/bid/20853http://www.vupen.com/english/advisories/2006/4141http://www.zerodayinitiative.com/advisories/ZDI-06-035.htmlhttp://www.zerodayinitiative.com/advisories/ZDI-06-036.htmlhttps://secure-support.novell.com/KanisaPlatform/Publishing/134/3096026_f.SAL_Public.htmlhttp://lists.grok.org.uk/pipermail/full-disclosure/2006-October/050382.htmlhttp://lists.grok.org.uk/pipermail/full-disclosure/2006-October/050388.htmlhttp://secunia.com/advisories/22519http://securitytracker.com/id?1017125http://securitytracker.com/id?1017141http://support.novell.com/cgi-bin/search/searchtid.cgi?/2974600.htmhttp://www.mnin.org/advisories/2006_novell_httpstk.pdfhttp://www.novell.com/support/search.do?cmd=displayKC&docType=kc&externalId=3723994&sliceId=SAL_Public&dialogID=16776123&stateId=1%200%202648401http://www.securityfocus.com/archive/1/449899/100/0/threadedhttp://www.securityfocus.com/archive/1/450017/100/0/threadedhttp://www.securityfocus.com/archive/1/450520/100/100/threadedhttp://www.securityfocus.com/bid/20655http://www.securityfocus.com/bid/20853http://www.vupen.com/english/advisories/2006/4141http://www.zerodayinitiative.com/advisories/ZDI-06-035.htmlhttp://www.zerodayinitiative.com/advisories/ZDI-06-036.htmlhttps://secure-support.novell.com/KanisaPlatform/Publishing/134/3096026_f.SAL_Public.html
2006-10-24
Published