Submit a Story      Security   FAQ    Resources    Certification    Links    Calendar    Forum    Polls    Search      
User Functions
:

:

Don't have an account yet? Sign up as a New User
Lost your password?

What's New
STORIES
No new stories

COMMENTS last 2 days
No new comments

TRACKBACKS last 2 days
No new trackback comments

LINKS last 2 weeks
No recent new links


Who's Online
Guest Users: 7

Live Novell Chat
Live Novell Chat

Topics
Home
Contracting (2/0)
FAQ (1/0)
NetWare (44/0)
Certification (26/0)
NDS/eDir (17/0)
Administration (77/0)
GroupWise (62/0)
Linux/Open Source (277/0)
Resources (16/0)
General News (649/0)
Security (179/0)

Poll
Best Virtualization Platform?
XEN
VMWare
M$ Virtual Centre
Other (please comment to identify)
Results
67 votes | 0 comments

Poll
Now that OES2 is out, what is your deployment strategy?
ASAP, it is not downloading fast enough!
Wait a few months
Wait for SP1
There is still a killer feature we need (if so denote in the comments)
Not at all
OES2? Is that the next version of OS/2?
Results
111 votes | 0 comments

Poll
Is 2008 finally the year Linux sees a bigger gain of marketshare on the desktop?
Yes. OEMs like Dell, HP and Lenovo selling Linux PCs, and better ATI driver support were the last major barriers to widespread adoption
No. Issues such as a lack of a unified package manager, lack of ISV support and lack of third party apps still need to be overcome.
Results
83 votes | 2 comments

Microsoft Security
  • Microsoft Security Bulletin Revisions
  • Microsoft Security Bulletin Summary for April 2008


  •  [SA29805] Novell eDirectory "Connection" HTTP Header Processing Denial of Service    
     Author:  kkbass
     Dated:  Tuesday, April 15 2008 @ 09:38 AM EDT
     Viewed:  58 times  
    SecuritySECUNIA ADVISORY ID:SA29805
    VERIFY ADVISORY:http://secunia.com/advisories/29805/
    CRITICAL:Less critical
    IMPACT:DoS
    WHERE:From local network

    SOFTWARE:
    Novell eDirectory 8.x
    http://secunia.com/product/1120/

    DESCRIPTION:
    A vulnerability has been reported in Novell eDirectory, which can be
    exploited by malicious people to cause a DoS (Denial of Service).

    The vulnerability is caused due to an error within dhost.exe when
    processing "Connection" headers in a HTTP request. This can be
    exploited to cause dhost.exe to consume large amounts of CPU resource
    via e.g. sending multiple HTTP requests containing specially crafted
    "Connection" headers.

    The vulnerability affects the following versions on Windows 2000/2003
    systems:
    * Novell eDirectory 8.8.1 and prior
    * Novell eDirectory 8.7.3.9 and prior

    SOLUTION:
    Update to version 8.8.2 or apply eDirectory 8.7.3 sp10.
    http://download.novell.com/

    PROVIDED AND/OR DISCOVERED BY:
    The vendor credits Nicholas Gregorie.

    ORIGINAL ADVISORY:
    Novell (3829452):
    http://www.novell.com/support/viewContent.do?externalId=3829452&sliceId=1

    ----------------------------------------------------------------------

    About:
    This Advisory was delivered by Secunia as a free service to help
    everybody keeping their systems up to date against the latest
    vulnerabilities.

    Subscribe:
    http://secunia.com/secunia_security_advisories/

    Definitions: (Criticality, Where etc.)
    http://secunia.com/about_secunia_advisories/


    Please Note:
    Secunia recommends that you verify all advisories you receive by
    clicking the link.
    Secunia NEVER sends attached files with advisories.
    Secunia does not advise people to install third party patches, only
    use those supplied by the vendor.

    ----------------------------------------------------------------------



    What's Related

    Story Options
  • Mail Story to a Friend
  • Printable Story Format

  • Trackback

    Trackback URL for this entry: http://www.abend.org/trackback.php/20080415093859170

    No trackback comments for this entry.
    [SA29805] Novell eDirectory "Connection" HTTP Header Processing Denial of Service | 0 comments | Create New Account
    The following comments are owned by whomever posted them. This site is not responsible for what they say.