what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

communiLDAP.txt

communiLDAP.txt
Posted Jan 29, 2006
Site gleg.net

Multiple vulnerabilities in the LDAP component of CommuniGate Pro Server version 5.0.6 have been uncovered.

tags | advisory, vulnerability
SHA-256 | c122b73e3f2aa436f247e447fbdaab96d30da06836b9880f9e41cca5aa1015ed

communiLDAP.txt

Change Mirror Download
I. DESCRIPTION

CommuniGate Pro Core Server from CommuniGate Systems provides robust cross-platform
groupware applications, enabling a cost effective, easy to manage communications platform.

For more info visit http://www.stalker.com

II. DETAILS

During testing of CommuniGate Pro Server 5.0.6 using ProtoVer LDAP testsuite version 1.1
multiple vulnerabilities in LDAP component of CommuniGate Pro have been uncovered.

The vulnerabilities could be used by a remote unauthenticated attacker to crash
the server or in the worst case to execute the arbitrary code.

III. VENDOR RESPONSE

The vendor has released 5.0.7 version which addresses these issues.
Quote from http://www.stalker.com/CommuniGatePro/History.html:

"""
5.0.7 27-Jan-05
Bug Fix: Foundation: 3.0: Negative BER lengths were processed incorrectly.
"""

IV. HISTORY

24 Jan 2006 - initial vendor contact
25 Jan 2006 - vendor received a fully-functional trial of ProtoVer LDAP testsuite
26 Jan 2006 - vendor successfully reproduced the problems
27 Jan 2006 - vendor released the fixed version

V. CREDIT

All these issues were found using GLEG Ltd's ProtoVer LDAP testsuite:
http://www.gleg.net/protover_ldap.shtml

Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    8 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    11 Files
  • 23
    Apr 23rd
    68 Files
  • 24
    Apr 24th
    23 Files
  • 25
    Apr 25th
    16 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close