vendor:
Groupwise
by:
Francis Provencher
7,5
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: Groupwise
Affected Version From: 8.0.2 HP3
Affected Version To: 2012
Patch Exists: Yes
Related CWE: SA50622
CPE: Novell:Groupwise
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2012
Novell Groupwise Vulnerability
The vulnerability is caused due to an overflow error in GroupWise Internet Agent (gwia.exe) when the LDAP service process an overly long BIND Request. Successful exploiataion of this vulnerability can allow a remote attacker to execute arbitrary code on the vulnerable system.
Mitigation:
Novell published a patch in 2012-09-14