Unrated severityNVD Advisory· Published Oct 14, 2008· Updated Apr 23, 2026
CVE-2008-4480
CVE-2008-4480
Description
Heap-based buffer overflow in dhost.exe in Novell eDirectory 8.x before 8.8.3, and 8.7.3 before 8.7.3.10 ftf1, allows remote attackers to execute arbitrary code via a crafted Netware Core Protocol opcode 0x24 message that triggers a calculation error that under-allocates a heap buffer.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
11- support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5037180.htmlnvdPatchVendor Advisory
- support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5037181.htmlnvdPatchVendor Advisory
- secunia.com/advisories/32111nvdThird Party Advisory
- securityreason.com/securityalert/4404nvdThird Party Advisory
- www.novell.com/support/php/search.donvdVendor Advisory
- www.novell.com/support/viewContent.donvdVendor Advisory
- www.novell.com/support/viewContent.donvdVendor Advisory
- www.securityfocus.com/archive/1/497169/100/0/threadednvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/idnvdThird Party AdvisoryVDB Entry
- www.vupen.com/english/advisories/2008/2738nvdThird Party Advisory
- www.zerodayinitiative.com/advisories/ZDI-08-066/nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.