Vulnerability record · CVE-2006-5478 · published 24 October 2006
CVE-2006-5478: Novell eDirectory and NetMail stack buffer overflows via HTTP and mail protocols
Novell · Edirectory
Novell eDirectory 8.8.x before 8.8.1 FTF1, 8.x up to 8.7.3.8, and NetMail before 3.52e FTF2 contain multiple stack-based buffer overflows. One is triggered by a long HTTP Host header in the BuildRedirectURL function; others involve a username containing a dot character across SMTP, POP, IMAP, HTTP, and NMAP NetMail services. Remote code execution is possible, making this a serious pre-authentication risk for exposed services.
Description
Multiple stack-based buffer overflows in Novell eDirectory 8.8.x before 8.8.1 FTF1, and 8.x up to 8.7.3.8, and Novell NetMail before 3.52e FTF2, allow remote attackers to execute arbitrary code via (1) a long HTTP Host header, which triggers an overflow in the BuildRedirectURL function; or vectors related to a username containing a . (dot) character in the (2) SMTP, (3) POP, (4) IMAP, (5) HTTP, or (6) Networked Messaging Application Protocol (NMAP) Netmail services.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityRemote, unauthenticated code execution with a very high EPSS score, though no KEV listing or confirmed in-the-wild exploitation is recorded.
What it is
Novell eDirectory 8.8.x before 8.8.1 FTF1, 8.x up to 8.7.3.8, and NetMail before 3.52e FTF2 contain multiple stack-based buffer overflows. One is triggered by a long HTTP Host header in the BuildRedirectURL function; others involve a username containing a dot character across SMTP, POP, IMAP, HTTP, and NMAP NetMail services. Remote code execution is possible, making this a serious pre-authentication risk for exposed services.
Impact
A remote attacker can overflow stack buffers and execute arbitrary code in the context of the affected service. Successful exploitation can lead to full compromise of the eDirectory or NetMail host.
Attack surface
Reachable over the network via HTTP (Host header) and via SMTP, POP, IMAP, HTTP, and NMAP services with a crafted username. The CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented. EPSS is very high (0.84, 99.7th percentile), and references include vendor advisories and patch links, but no public exploit tag is present in the record.
What to do
- Apply the vendor patches: eDirectory 8.8.1 FTF1 or later, and NetMail 3.52e FTF2 or later.
- Restrict network access to eDirectory and NetMail service ports (HTTP, SMTP, POP, IMAP, NMAP) to trusted hosts only.
- Disable or block unused mail and HTTP services on affected systems.
- Monitor vendor advisories for updated fixes and validate the installed build version.
- Segment legacy eDirectory/NetMail deployments away from untrusted networks.
Detection
- Inspect HTTP request logs for abnormally long Host headers targeting eDirectory/NetMail web services.
- Search mail and NMAP service logs for usernames containing dot characters that are unusually long or malformed.
- Monitor for crashes or restarts of eDirectory/NetMail service processes that could indicate overflow attempts.
- Use network IDS signatures for oversized Host headers and malformed username fields on the affected ports.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2006-5478 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2006-5478), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.