PT-2012-2452 · Novell · Novell Groupwise

Published

2012-09-19

·

Updated

2013-04-02

·

CVE-2012-0271

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Novell GroupWise versions 8.0 through 8.0.3 HP1 and 2012 before SP1
Description The issue is related to an integer overflow in the WebConsole component of the GroupWise Internet Agent (GWIA), which could potentially allow remote attackers to execute arbitrary code. This can be triggered by a crafted request, such as one with -1 in the Content-Length HTTP header, leading to a heap-based buffer overflow.
Recommendations For Novell GroupWise versions 8.0 through 8.0.3 HP1, update to version 8.0.3 HP1 or later. For Novell GroupWise 2012 before SP1, update to SP1 or later.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-0271

Affected Products

Novell Groupwise