---------------------------------------------------------------------- Secunia Network Software Inspector 2.0 (NSI) - Public Beta 16 days left of beta period. The 1st generation of the Secunia Network Software Inspector (NSI) has been available for corporate users for almost 1 year and its been a tremendous success. The 2nd generation Secunia NSI is built on the same technology as the award winning Secunia PSI, which has already been downloaded and installed on more than 400,000 computers world wide. Learn more / Download (instant access): http://secunia.com/network_software_inspector_2/ ---------------------------------------------------------------------- TITLE: Novell eDirectory "Connection" HTTP Header Processing Denial of Service SECUNIA ADVISORY ID: SA29805 VERIFY ADVISORY: http://secunia.com/advisories/29805/ CRITICAL: Less critical IMPACT: DoS WHERE: >From local network SOFTWARE: Novell eDirectory 8.x http://secunia.com/product/1120/ DESCRIPTION: A vulnerability has been reported in Novell eDirectory, which can be exploited by malicious people to cause a DoS (Denial of Service). The vulnerability is caused due to an error within dhost.exe when processing "Connection" headers in a HTTP request. This can be exploited to cause dhost.exe to consume large amounts of CPU resource via e.g. sending multiple HTTP requests containing specially crafted "Connection" headers. The vulnerability affects the following versions on Windows 2000/2003 systems: * Novell eDirectory 8.8.1 and prior * Novell eDirectory 8.7.3.9 and prior SOLUTION: Update to version 8.8.2 or apply eDirectory 8.7.3 sp10. http://download.novell.com/ PROVIDED AND/OR DISCOVERED BY: The vendor credits Nicholas Gregorie. ORIGINAL ADVISORY: Novell (3829452): http://www.novell.com/support/viewContent.do?externalId=3829452&sliceId=1 ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help everybody keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------