CVE-2008-0924
published 2008-03-28CVE-2008-0924: Stack-based buffer overflow in the DoLBURPRequest function in libnldap in ndsd in Novell eDirectory 8.7.3.9 and earlier, and 8.8.1 and earlier in the 8.8.x…
PriorityP335medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
5.00%
91.3th percentile
Stack-based buffer overflow in the DoLBURPRequest function in libnldap in ndsd in Novell eDirectory 8.7.3.9 and earlier, and 8.8.1 and earlier in the 8.8.x series, allows remote attackers to cause a denial of service (daemon crash or CPU consumption) or execute arbitrary code via a long delRequest LDAP Extended Request message, probably involving a long Distinguished Name (DN) field.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| novell | edirectory | 8.7 – 8.7.3.9 | — |
| novell | edirectory | 8.8 – 8.8.1 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2008-3829 condor: denial of service attack on Schedd via corrupt logfile
bugzilla·2008-09-25·CVSS 5.0
CVE-2008-3829 [MEDIUM] CVE-2008-3829 condor: denial of service attack on Schedd via corrupt logfile
CVE-2008-3829 condor: denial of service attack on Schedd via corrupt logfile
A denial of service flaw was discovered in the Condor's Schedd. A user who
has permission to submit a job could do so in a way that will cause
corruption of the job_queue.log file, preventing Schedd from running.
Discussion:
Lifting embargo:
http://www.cs.wisc.edu/condor/manual/v7.0/8_3Stable_Release.html#SECTION00931000000000000000
---
condor-7.0.5-1.fc9 has been pushed to the Fedora 9 stable repository. If problems still persist, please make note of it in this bug report.
---
This issue was addressed in:
Red Hat Enterprise MRG for RHEL-4:
http://rhn.redhat.com/errata/RHSA-2008-0924.html
Red Hat Enterprise MRG for RHEL-5:
http://rhn.redhat.com/errata/RHSA-2008-0911.html
Fedora:
https://admin.fedoraproje
Bugzilla
CVE-2008-3826 condor: users can run jobs with arbitrary owners
bugzilla·2008-09-25·CVSS 4.6
CVE-2008-3826 [MEDIUM] CVE-2008-3826 condor: users can run jobs with arbitrary owners
CVE-2008-3826 condor: users can run jobs with arbitrary owners
A user with permission to submit jobs can run any program on a pool as any
user.
The job is submitted and the Owner is quickly changed to the victim. The
victim's account will be used to run the job. The job can run any program
and be directed to any machine within the pool.
This flaw cannot be used to execute arbitrary jobs as the root superuser.
Discussion:
Lifting embargo:
http://www.cs.wisc.edu/condor/manual/v7.0/8_3Stable_Release.html#SECTION00931000000000000000
---
condor-7.0.5-1.fc9 has been pushed to the Fedora 9 stable repository. If problems still persist, please make note of it in this bug report.
---
This issue was addressed in:
Red Hat Enterprise MRG for RHEL-4:
http://rhn.redhat.com/errata/RHSA-2008-0924
Bugzilla
CVE-2008-3830 condor: allow or deny with overlapping netmasks may be ignored
bugzilla·2008-09-25·CVSS 7.2
CVE-2008-3830 [HIGH] CVE-2008-3830 condor: allow or deny with overlapping netmasks may be ignored
CVE-2008-3830 condor: allow or deny with overlapping netmasks may be ignored
Configurations that have entries in the allow or deny lists which specify
overlapping netmasks. For example, *, 192.*, and 192.168.* are overlapping
netmasks.
The consequence of the bug is that some allow/deny entries may be ignored.
Discussion:
Lifting embargo:
http://www.cs.wisc.edu/condor/manual/v7.0/8_3Stable_Release.html#SECTION00931000000000000000
---
condor-7.0.5-1.fc9 has been pushed to the Fedora 9 stable repository. If problems still persist, please make note of it in this bug report.
---
This issue was addressed in:
Red Hat Enterprise MRG for RHEL-4:
http://rhn.redhat.com/errata/RHSA-2008-0924.html
Red Hat Enterprise MRG for RHEL-5:
http://rhn.redhat.com/errata/RHSA-2008-0911.html
Fedora:
htt
http://secunia.com/advisories/29476http://www.securityfocus.com/archive/1/490117/100/0/threadedhttp://www.securityfocus.com/bid/28434http://www.securitytracker.com/id?1019692http://www.vupen.com/english/advisories/2008/0987/referenceshttp://www.zerodayinitiative.com/advisories/ZDI-08-013/https://secure-support.novell.com/KanisaPlatform/Publishing/411/3382120_f.SAL_Public.htmlhttp://secunia.com/advisories/29476http://www.securityfocus.com/archive/1/490117/100/0/threadedhttp://www.securityfocus.com/bid/28434http://www.securitytracker.com/id?1019692http://www.vupen.com/english/advisories/2008/0987/referenceshttp://www.zerodayinitiative.com/advisories/ZDI-08-013/https://secure-support.novell.com/KanisaPlatform/Publishing/411/3382120_f.SAL_Public.html
2008-03-28
Published