René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

107 lines
3.2 KiB
JSON

{
"id": "CVE-2006-4510",
"sourceIdentifier": "cve@mitre.org",
"published": "2006-10-24T19:07:00.000",
"lastModified": "2017-07-20T01:33:08.790",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "The evtFilteredMonitorEventsRequest function in the LDAP service in Novell eDirectory before 8.8.1 FTF1 allows remote attackers to execute arbitrary code via a crafted request containing a value that is larger than the number of objects transmitted, which triggers an invalid free of unallocated memory."
},
{
"lang": "es",
"value": "La funci\u00f3n evtFilteredMonitorEventsRequest en el servicio LDAP en Novell eDirectory anterior a 8.8.1 FTF1 permite a atacantes remotos ejecutar c\u00f3digo de su elecci\u00f3n mediante una petici\u00f3n artesanal que contiene un valor m\u00e1s largo que el n\u00famero de objetos transmitidos, lo cual dispara una liberaci\u00f3n inv\u00e1lida de memoria no asignada."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "COMPLETE",
"integrityImpact": "COMPLETE",
"availabilityImpact": "COMPLETE",
"baseScore": 10.0
},
"baseSeverity": "HIGH",
"exploitabilityScore": 10.0,
"impactScore": 10.0,
"acInsufInfo": false,
"obtainAllPrivilege": true,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:novell:edirectory:8.8:*:*:*:*:*:*:*",
"matchCriteriaId": "D7548D05-AD2B-46C3-9036-366585FFCB48"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:novell:edirectory:8.8.1:*:*:*:*:*:*:*",
"matchCriteriaId": "C13882AD-D700-4B95-9BB2-B3E0D104B227"
}
]
}
]
}
],
"references": [
{
"url": "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=428",
"source": "cve@mitre.org",
"tags": [
"Patch",
"Vendor Advisory"
]
},
{
"url": "http://securitytracker.com/id?1017104",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/20663",
"source": "cve@mitre.org",
"tags": [
"Patch"
]
},
{
"url": "http://www.vupen.com/english/advisories/2006/4142",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/29752",
"source": "cve@mitre.org"
}
]
}