|
Brought to you by:
Suppliers of:
|
|
|
| |
Two critical vulnerabilities affecting Novell GroupWise 8.x and 7.x have been discovered.
The first issue is caused due to a buffer overflow error in the Novell GroupWise Internet Agent (GWIA) when processing specially crafted email addresses via SMTP, which could be exploited by remote unauthenticated attackers to execute arbitrary code with SYSTEM privileges.
The second vulnerability is caused due to a buffer overflow error in the Novell GroupWise Internet Agent (GWIA) when processing certain SMTP requests, which could be exploited by remote unauthenticated attackers to execute arbitrary code with SYSTEM privileges. |
| |
Credit:
The information has been provided by Nicolas JOLY.
The original article can be found at: http://www.vupen.com/english/advisories/2009/1393
|
| |
Vulnerable Systems:
* Novell GroupWise version 7.03 HP2 and prior
* Novell GroupWise version 8.0.0 HP1 and prior
Patch Availability:
For GroupWise 7.x systems, apply GroupWise 7.03 Hot Patch 3 (HP3) or later
For GroupWise 8.0 systems, apply GroupWise 8.0 Hot Patch 2 (HP2) or later
CVE Information:
CVE-2009-1636
Vendor Response:
http://www.novell.com/support/viewContent.do?externalId=7003273&sliceId=1 http://www.novell.com/support/viewContent.do?externalId=7003272&sliceId=1
Disclosure Timeline:
18/02/2009 - Vendor notified
18/02/2009 - Vendor response
21/05/2009 - Vendor issues fixed version
22/05/2009 - Coordinated public Disclosure
|
|
|
|
|