Denial of Service Vulnerability in Novell eDirectory Software
CVE-2008-0927

Currently unrated

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
14 April 2008

What is CVE-2008-0927?

The vulnerability in Novell eDirectory occurs when dhost.exe does not properly handle HTTP requests containing multiple Connection headers or comma-separated values in a single Connection header. This improper handling allows attackers to cause excessive CPU consumption, leading to service interruptions. By executing specially crafted HTTP requests, malicious users can exploit this vulnerability remotely, effectively disrupting the normal operation of the eDirectory service.

References

EPSS Score

85% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.