PT-2013-1498 · Novell · Novell Groupwise

Andrea Micalizzi

+1

·

Publicado

2013-02-01

·

Atualizado

2013-02-25

·

CVE-2012-0439

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Novell GroupWise versions 8.0 through 8.0.3 HP2 Novell GroupWise 2012 versions prior to SP1 HP1
Description The issue allows remote attackers to execute arbitrary code. This can be achieved via a pointer argument to the SetEngine method or an XPItem pointer argument to an unspecified method in the ActiveX control in gwcls1.dll.
Recommendations For Novell GroupWise versions 8.0 through 8.0.3 HP2, update to version 8.0.3 HP2 or later. For Novell GroupWise 2012 versions prior to SP1 HP1, update to SP1 HP1 or later. As a temporary workaround, consider disabling the ActiveX control in gwcls1.dll until a patch is available.

Exploit

Correção

RCE

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-0439
ZDI-13-008

Produtos afetados

Novell Groupwise