PT-2002-2093 · Novell · Novell Groupwise
Published
2002-10-04
·
Updated
2008-09-05
·
CVE-2002-1088
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Novell GroupWise version 6.0.1 Support Pack 1
Description:
The issue allows remote attackers to execute arbitrary code via a long RCPT TO command, which is related to a buffer overflow.
Recommendations:
For Novell GroupWise version 6.0.1 Support Pack 1, consider applying a patch or update to fix the buffer overflow issue. As a temporary workaround, restrict access to the RCPT TO command to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Novell Groupwise