PT-2013-1498 · Novell · Novell Groupwise

Andrea Micalizzi

+1

·

Published

2013-02-01

·

Updated

2013-02-25

·

CVE-2012-0439

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Novell GroupWise versions 8.0 through 8.0.3 HP2 Novell GroupWise 2012 versions prior to SP1 HP1
Description The issue allows remote attackers to execute arbitrary code. This can be achieved via a pointer argument to the SetEngine method or an XPItem pointer argument to an unspecified method in the ActiveX control in gwcls1.dll.
Recommendations For Novell GroupWise versions 8.0 through 8.0.3 HP2, update to version 8.0.3 HP2 or later. For Novell GroupWise 2012 versions prior to SP1 HP1, update to SP1 HP1 or later. As a temporary workaround, consider disabling the ActiveX control in gwcls1.dll until a patch is available.

Exploit

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-0439
ZDI-13-008

Affected Products

Novell Groupwise