PT-2012-2452 · Novell · Novell Groupwise

Publicado

2012-09-19

·

Atualizado

2013-04-02

·

CVE-2012-0271

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Novell GroupWise versions 8.0 through 8.0.3 HP1 and 2012 before SP1
Description The issue is related to an integer overflow in the WebConsole component of the GroupWise Internet Agent (GWIA), which could potentially allow remote attackers to execute arbitrary code. This can be triggered by a crafted request, such as one with -1 in the Content-Length HTTP header, leading to a heap-based buffer overflow.
Recommendations For Novell GroupWise versions 8.0 through 8.0.3 HP1, update to version 8.0.3 HP1 or later. For Novell GroupWise 2012 before SP1, update to SP1 or later.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-0271

Produtos afetados

Novell Groupwise