Novell GroupWise Internet Agent Remote Buffer Overflow Vulnerabilities
25 May 2009
Summary
Two critical vulnerabilities affecting Novell GroupWise 8.x and 7.x have been discovered.
The first issue is caused due to a buffer overflow error in the Novell GroupWise Internet Agent (GWIA) when processing specially crafted email addresses via SMTP, which could be exploited by remote unauthenticated attackers to execute arbitrary code with SYSTEM privileges.
The second vulnerability is caused due to a buffer overflow error in the Novell GroupWise Internet Agent (GWIA) when processing certain SMTP requests, which could be exploited by remote unauthenticated attackers to execute arbitrary code with SYSTEM privileges.
Vulnerable Systems:
* Novell GroupWise version 7.03 HP2 and prior
* Novell GroupWise version 8.0.0 HP1 and prior
Patch Availability:
For GroupWise 7.x systems, apply GroupWise 7.03 Hot Patch 3 (HP3) or later
For GroupWise 8.0 systems, apply GroupWise 8.0 Hot Patch 2 (HP2) or later