Applicaton control request overflow (Application_Control_Request_Overflow)

About this signature or vulnerability

Proventia Network IPS, Proventia Desktop, RealSecure Network, RealSecure Server Sensor, Proventia-G 1.1 and earlier, Proventia Network IDS, Proventia Network MFS, IBM Security Server Protection for Windows, Proventia Server IPS for Linux technology, Virtual Server Protection for Vmware:

This event triggers when a specially crafted protocol event is detected that could cause a buffer overflow in a network control application.


False positives

RealSecure Network, IBM Security Server Protection for Windows: No false postives are known at this time.

False negatives

RealSecure Network, IBM Security Server Protection for Windows: No false negatives are known at this time.

Default risk level

High risk vulnerability  High

Sensors that have this signature

Proventia Network IPS: XPU 29.060, Proventia Desktop: 2400, RealSecure Network: XPU 29.060, RealSecure Server Sensor: XPU 29.060, Proventia-G 1.1 and earlier: XPU 29.060, Proventia Network IDS: XPU 29.060, Proventia Network MFS: XPU 29.060, IBM Security Server Protection for Windows: 2.0.300.2400, IBM Security Server Protection for Windows: 1.0.914.2400, IBM Security Server Protection for Windows: 2.1.14.2400, Proventia Server IPS for Linux technology: 29.060, Virtual Server Protection for Vmware: 1.0

Systems affected

Novell eDirectory: 8.7.3, Novell eDirectory: 8.8, Application Application Control

Type

Unauthorized Access Attempt

Vulnerability description

Novell eDirectory is vulnerable to a heap-based buffer overflow, caused by an integer overflow. By sending a specially-crafted service request, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.

How to remove this vulnerability

Refer to Novell Document ID: 7004912 for patch, upgrade or suggested workaround information. See References.

References

IBM Internet Security Systems Protection Advisory
Novell eDirectory Remote Code Execution
http://www.iss.net/threats/356.html

Novell Document ID: 7004912
Novell eDirectory Heap-based Buffer Overflow
http://www.novell.com/support/viewContent.do?externalId=7004912&sliceId=1

Novell Web site
Novell eDirectory
http://www.novell.com/products/edirectory/

ISS X-Force
Applicaton control request overflow
http://www.iss.net/security_center/static/50616.php

CVE
CVE-2009-0895
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0895