Vulnerable Systems:
*GroupWise Client 8.0.3 HP1 and prior
Novell GroupWise Client contains a flaw in the gwcls1.dll ActiveX control. The issue is due to multiple methods accepting XPItem pointers without validating them first. Additionally the SetEngine() method accepts unvalidated pointers and potentially uses these in method calls. This may allow a context-dependent attacker to execute arbitrary code.