PT-2013-1498 · Novell · Novell Groupwise
Andrea Micalizzi
+1
·
Publicado
2013-02-01
·
Atualizado
2013-02-25
·
CVE-2012-0439
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Novell GroupWise versions 8.0 through 8.0.3 HP2
Novell GroupWise 2012 versions prior to SP1 HP1
Description
The issue allows remote attackers to execute arbitrary code. This can be achieved via a pointer argument to the
SetEngine method or an XPItem pointer argument to an unspecified method in the ActiveX control in gwcls1.dll.Recommendations
For Novell GroupWise versions 8.0 through 8.0.3 HP2, update to version 8.0.3 HP2 or later.
For Novell GroupWise 2012 versions prior to SP1 HP1, update to SP1 HP1 or later.
As a temporary workaround, consider disabling the ActiveX control in gwcls1.dll until a patch is available.
Exploit
Correção
RCE
Code Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Novell Groupwise