Security Vulnerability: eDirectory LDAP Null Base DN Denial of Service

This document (7004721) is provided subject to the disclaimer at the end of this document.

Environment

Novell eDirectory 8.8 for All Platforms
Novell eDirectory 8.7.3 for All Platforms

Situation

A flaw exists in eDirectory's LDAP which can cause the eDirectory service to become unresponsive when processing a malformed search request with a NULL BaseDN.

Resolution

This vulnerability is resolved in eDirectory 8.8.5 ftf1 and eDirectory 8.7.3.10 ftf2.

To resolve this problem, apply eDirectory 8.8.5 ftf1 or newer for eDirectory 8.8.X and eDirectory 8.7.3.10 ftf2 for eDirectory 8.7.3.X.  Patches are available at http://download.novell.com

Status

Reported to Engineering
Security Alert

Additional Information

This vulnerability was reported by Zero Day Initiative (ZDI) estabilished by TippingPoint, a division of 3Com.

ZDI-CAN-513: Novell eDirectory LDAP Null Based DN Denial of Service

http://www.zerodayinitiative.com/advisories/ZDI-CAN-214.html

Document

Document ID:7004721
Creation Date:10-21-2009
Modified Date:10-22-2009
Novell Product:eDirectory

Disclaimer

The Origin of this information may be internal or external to Novell. Novell makes all reasonable efforts to verify this information. However, the information provided in this document is for your information only. Novell makes no explicit or implied claims to the validity of this information.
Any trademarks referenced in this document are the property of their respective owners. Consult your product manuals for complete trademark information.