vendor:
GroupWise Messenger
by:
Luigi Auriemma
7,5
CVSS
HIGH
Memory Corruption
119
CWE
Product Name: GroupWise Messenger
Affected Version From: <= 2.1.0
Affected Version To: <= 2.1.0
Patch Exists: YES
Related CWE: N/A
CPE: a:novell:groupwise_messenger
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, NetWare
2012
Memory Corruption in Novell GroupWise Messenger
nmma.exe is a service running on port 8300. The NM_A_PARM1 tag of the 'login' command is the base64 of the 'username::password' string encrypted with blowfish. This tag has the value 10 which is relative to the strings, but exists another type defined as 12 which instead is used for particular data ('nested arrays') and when used for login->NM_A_PARM1 allows to corrupt the heap memory. Through additional packets before and after the malformed one (the service is multi-thread) may be possible to control the memory and execute arbitrary code.
Mitigation:
Upgrade to the latest version of Novell GroupWise Messenger