PT-2017-2110 · Novell · Novell Groupwise
W. Ettlinger
·
Published
2017-04-20
·
Updated
2019-05-30
·
CVE-2016-5762
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Novell GroupWise versions prior to 2014 R2 Service Pack 1 Hot Patch 1
Description
The issue is caused by an integer overflow in the Post Office Agent, which can be exploited by remote attackers to execute arbitrary code. This can be achieved by using a long
username or password, triggering a heap-based buffer overflow.Recommendations
For versions prior to 2014 R2 Service Pack 1 Hot Patch 1, update to 2014 R2 Service Pack 1 Hot Patch 1 or later to resolve the issue. As a temporary workaround, consider restricting the length of
username and password inputs to prevent exploitation.Exploit
Fix
RCE
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Novell Groupwise