← Vulnerability feed

Vulnerability record · CVE-2006-5478 · published 24 October 2006

CVE-2006-5478: Novell eDirectory and NetMail stack buffer overflows via HTTP and mail protocols

Novell · Edirectory

Novell eDirectory 8.8.x before 8.8.1 FTF1, 8.x up to 8.7.3.8, and NetMail before 3.52e FTF2 contain multiple stack-based buffer overflows. One is triggered by a long HTTP Host header in the BuildRedirectURL function; others involve a username containing a dot character across SMTP, POP, IMAP, HTTP, and NMAP NetMail services. Remote code execution is possible, making this a serious pre-authentication risk for exposed services.

7.5 CVSS 2.0 High EPSS 85% · top 0.3% CWE-119 · Memory buffer overflow
7.5CVSS 2.0 base score
85%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
34References
16 Jun 2026Last modified by NVD

Description

Multiple stack-based buffer overflows in Novell eDirectory 8.8.x before 8.8.1 FTF1, and 8.x up to 8.7.3.8, and Novell NetMail before 3.52e FTF2, allow remote attackers to execute arbitrary code via (1) a long HTTP Host header, which triggers an overflow in the BuildRedirectURL function; or vectors related to a username containing a . (dot) character in the (2) SMTP, (3) POP, (4) IMAP, (5) HTTP, or (6) Networked Messaging Application Protocol (NMAP) Netmail services.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityRemote, unauthenticated code execution with a very high EPSS score, though no KEV listing or confirmed in-the-wild exploitation is recorded.

What it is

Novell eDirectory 8.8.x before 8.8.1 FTF1, 8.x up to 8.7.3.8, and NetMail before 3.52e FTF2 contain multiple stack-based buffer overflows. One is triggered by a long HTTP Host header in the BuildRedirectURL function; others involve a username containing a dot character across SMTP, POP, IMAP, HTTP, and NMAP NetMail services. Remote code execution is possible, making this a serious pre-authentication risk for exposed services.

Impact

A remote attacker can overflow stack buffers and execute arbitrary code in the context of the affected service. Successful exploitation can lead to full compromise of the eDirectory or NetMail host.

Attack surface

Reachable over the network via HTTP (Host header) and via SMTP, POP, IMAP, HTTP, and NMAP services with a crafted username. The CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV and no ransomware associations are documented. EPSS is very high (0.84, 99.7th percentile), and references include vendor advisories and patch links, but no public exploit tag is present in the record.

What to do

  • Apply the vendor patches: eDirectory 8.8.1 FTF1 or later, and NetMail 3.52e FTF2 or later.
  • Restrict network access to eDirectory and NetMail service ports (HTTP, SMTP, POP, IMAP, NMAP) to trusted hosts only.
  • Disable or block unused mail and HTTP services on affected systems.
  • Monitor vendor advisories for updated fixes and validate the installed build version.
  • Segment legacy eDirectory/NetMail deployments away from untrusted networks.

Detection

  • Inspect HTTP request logs for abnormally long Host headers targeting eDirectory/NetMail web services.
  • Search mail and NMAP service logs for usernames containing dot characters that are unusually long or malformed.
  • Monitor for crashes or restarts of eDirectory/NetMail service processes that could indicate overflow attempts.
  • Use network IDS signatures for oversized Host headers and malformed username fields on the affected ports.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.grok.org.uk/pipermail/full-disclosure/2006-October/050382.html
http://lists.grok.org.uk/pipermail/full-disclosure/2006-October/050388.html
http://secunia.com/advisories/22519 PatchVendor Advisory
http://securitytracker.com/id?1017125
http://securitytracker.com/id?1017141
http://support.novell.com/cgi-bin/search/searchtid.cgi?/2974600.htm Patch
http://www.mnin.org/advisories/2006_novell_httpstk.pdf Vendor Advisory
http://www.novell.com/support/search.do?cmd=displayKC&docType=kc&externalId=3723994&sliceId=SAL_Public&dialogID=16776123
http://www.securityfocus.com/archive/1/449899/100/0/threaded
http://www.securityfocus.com/archive/1/450017/100/0/threaded
http://www.securityfocus.com/archive/1/450520/100/100/threaded
http://www.securityfocus.com/bid/20655
http://www.securityfocus.com/bid/20853
http://www.vupen.com/english/advisories/2006/4141 Vendor Advisory
http://www.zerodayinitiative.com/advisories/ZDI-06-035.html
http://www.zerodayinitiative.com/advisories/ZDI-06-036.html
https://secure-support.novell.com/KanisaPlatform/Publishing/134/3096026_f.SAL_Public.html
http://lists.grok.org.uk/pipermail/full-disclosure/2006-October/050382.html
http://lists.grok.org.uk/pipermail/full-disclosure/2006-October/050388.html
http://secunia.com/advisories/22519 PatchVendor Advisory
http://securitytracker.com/id?1017125
http://securitytracker.com/id?1017141
http://support.novell.com/cgi-bin/search/searchtid.cgi?/2974600.htm Patch
http://www.mnin.org/advisories/2006_novell_httpstk.pdf Vendor Advisory
http://www.novell.com/support/search.do?cmd=displayKC&docType=kc&externalId=3723994&sliceId=SAL_Public&dialogID=16776123
http://www.securityfocus.com/archive/1/449899/100/0/threaded
http://www.securityfocus.com/archive/1/450017/100/0/threaded
http://www.securityfocus.com/archive/1/450520/100/100/threaded
http://www.securityfocus.com/bid/20655
http://www.securityfocus.com/bid/20853
http://www.vupen.com/english/advisories/2006/4141 Vendor Advisory
http://www.zerodayinitiative.com/advisories/ZDI-06-035.html
http://www.zerodayinitiative.com/advisories/ZDI-06-036.html
https://secure-support.novell.com/KanisaPlatform/Publishing/134/3096026_f.SAL_Public.html

Track CVE-2006-5478 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2009-0895Novell edirectory vulnerabilityInteger overflow in Novell eDirectory 8.7.3.x before 8.7.3.10 ftf2 and 8.8.x before 8.8.5.2 allows remote attackers to execute arbitrary code via an …EPSS 6.8%10.0CVE-2008-5091Novell edirectory memory buffer overflow vulnerabilityBuffer overflow in the LDAP Service in Novell eDirectory 8.7.3 before SP10a and 8.8 before SP3 allows attackers to cause a denial of service (applica…EPSS 2.1%10.0CVE-2008-5092Novell edirectory memory buffer overflow vulnerabilityHeap-based buffer overflows in Novell eDirectory HTTP protocol stack (HTTPSTK) before 8.8 SP3 have unknown impact and attack vectors related to the (…EPSS 1.7%10.0CVE-2008-5094Novell edirectory memory buffer overflow vulnerabilityHeap-based buffer overflow in the NDS Service in Novell eDirectory before 8.8 SP3 has unknown impact and attack vectors.EPSS 1.7%10.0CVE-2008-4479Novell edirectory memory buffer overflow vulnerabilityHeap-based buffer overflow in dhost.exe in Novell eDirectory 8.8 before 8.8.3, and 8.7.3 before 8.7.3.10 ftf1, allows remote attackers to execute arb…EPSS 10%10.0CVE-2008-4480Novell edirectory memory buffer overflow vulnerabilityHeap-based buffer overflow in dhost.exe in Novell eDirectory 8.x before 8.8.3, and 8.7.3 before 8.7.3.10 ftf1, allows remote attackers to execute arb…EPSS 11%10.0CVE-2008-4478Novell edirectory vulnerabilityMultiple integer overflows in dhost.exe in Novell eDirectory 8.8 before 8.8.3, and 8.73 before 8.7.3.10 ftf1, allow remote attackers to execute arbit…EPSS 9.8%10.0CVE-2008-1809Novell edirectory memory buffer overflow vulnerabilityHeap-based buffer overflow in Novell eDirectory 8.7.3 before 8.7.3.10b, and 8.8 before 8.8.2 FTF2, allows remote attackers to execute arbitrary code …EPSS 5.7%

Source: NIST National Vulnerability Database (record CVE-2006-5478), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.