vendor:
Groupwise Messenger Server
by:
H D Moore
7.5
CVSS
HIGH
Stack Overflow
119
CWE
Product Name: Groupwise Messenger Server
Affected Version From: Groupwise Messenger DClient.dll v10510.37
Affected Version To: Groupwise Messenger DClient.dll v10510.37
Patch Exists: YES
Related CWE: CVE-2006-0992
CPE: a:novell:groupwise_messenger_server:2.0
Metasploit:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2006
Novell Messenger Server 2.0 Accept-Language Overflow
This module exploits a stack overflow in Novell GroupWise Messenger Server v2.0. This flaw is triggered by any HTTP request with an Accept-Language header greater than 16 bytes. To overwrite the return address on the stack, we must first pass a memcpy() operation that uses pointers we supply. Due to the large list of restricted characters and the limitations of the current encoder modules, very few payloads are usable. The 'known good' set includes win32_adduser, win32_exec, and win32_reverse_ord;
Mitigation:
Upgrade to the latest version of Novell GroupWise Messenger Server