CVE-2008-0927

Severity CVSS v4.0:
Pending analysis
Type:
CWE-399 Resource Management Errors
Publication date:
14/04/2008
Last modified:
09/04/2025

Description

dhost.exe in Novell eDirectory 8.7.3 before sp10 and 8.8.2 allows remote attackers to cause a denial of service (CPU consumption) via an HTTP request with (1) multiple Connection headers or (2) a Connection header with multiple comma-separated values. NOTE: this might be similar to CVE-2008-1777.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:novell:edirectory:*:*:*:*:*:*:*:* 8.7.3.9 (including)
cpe:2.3:a:novell:edirectory:*:*:*:*:*:*:*:* 8.8 (including) 8.8.2 (excluding)
cpe:2.3:o:microsoft:windows-nt:2000:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows-nt:2003:*:*:*:*:*:*:*