Proventia Network IPS, Proventia Desktop, RealSecure Network, RealSecure Server Sensor, Proventia-G 1.1 and earlier, Proventia Network IDS, Proventia Network MFS, IBM Security Server Protection for Windows, Proventia Server IPS for Linux technology, Virtual Server Protection for Vmware:
This event triggers when a specially crafted protocol event is detected that could cause a buffer overflow in a network control application.
RealSecure Network, IBM Security Server Protection for Windows: No false postives are known at this time.
RealSecure Network, IBM Security Server Protection for Windows: No false negatives are known at this time.
High
Proventia Network IPS: XPU 29.060, Proventia Desktop: 2400, RealSecure Network: XPU 29.060, RealSecure Server Sensor: XPU 29.060, Proventia-G 1.1 and earlier: XPU 29.060, Proventia Network IDS: XPU 29.060, Proventia Network MFS: XPU 29.060, IBM Security Server Protection for Windows: 2.0.300.2400, IBM Security Server Protection for Windows: 1.0.914.2400, IBM Security Server Protection for Windows: 2.1.14.2400, Proventia Server IPS for Linux technology: 29.060, Virtual Server Protection for Vmware: 1.0
Novell eDirectory: 8.7.3, Novell eDirectory: 8.8, Application Application Control
Unauthorized Access Attempt
Novell eDirectory is vulnerable to a heap-based buffer overflow, caused by an integer overflow. By sending a specially-crafted service request, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.
Refer to Novell Document ID: 7004912 for patch, upgrade or suggested workaround information. See References.
IBM Internet Security Systems Protection Advisory
Novell eDirectory Remote Code Execution
http://www.iss.net/threats/356.html
Novell Document ID: 7004912
Novell eDirectory Heap-based Buffer Overflow
http://www.novell.com/support/viewContent.do?externalId=7004912&sliceId=1
Novell Web site
Novell eDirectory
http://www.novell.com/products/edirectory/
ISS X-Force
Applicaton control request overflow
http://www.iss.net/security_center/static/50616.php
CVE
CVE-2009-0895
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0895