PT-2002-2093 · Novell · Novell Groupwise

Published

2002-10-04

·

Updated

2008-09-05

·

CVE-2002-1088

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Novell GroupWise version 6.0.1 Support Pack 1
Description: The issue allows remote attackers to execute arbitrary code via a long RCPT TO command, which is related to a buffer overflow.
Recommendations: For Novell GroupWise version 6.0.1 Support Pack 1, consider applying a patch or update to fix the buffer overflow issue. As a temporary workaround, restrict access to the RCPT TO command to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-1088

Affected Products

Novell Groupwise