VYPR
Unrated severityNVD Advisory· Published Nov 4, 2006· Updated Jun 16, 2026

CVE-2006-4521

CVE-2006-4521

Description

The BerDecodeLoginDataRequest function in the libnmasldap.so NMAS module in Novell eDirectory 8.8 and 8.8.1 before the Security Services 2.0.3 patch does not properly increment a pointer when handling certain input, which allows remote attackers to cause a denial of service (invalid memory access) via a crafted login request.

Affected products

3
  • Novell/Edirectory3 versions
    cpe:2.3:a:novell:edirectory:8.8:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:novell:edirectory:8.8:*:*:*:*:*:*:*
    • cpe:2.3:a:novell:edirectory:8.8.1:*:*:*:*:*:*:*
    • (no CPE)range: 8.8, 8.8.1 before Security Services 2.0.3

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.