PT-2017-2110 · Novell · Novell Groupwise

W. Ettlinger

·

Published

2017-04-20

·

Updated

2019-05-30

·

CVE-2016-5762

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Novell GroupWise versions prior to 2014 R2 Service Pack 1 Hot Patch 1
Description The issue is caused by an integer overflow in the Post Office Agent, which can be exploited by remote attackers to execute arbitrary code. This can be achieved by using a long username or password, triggering a heap-based buffer overflow.
Recommendations For versions prior to 2014 R2 Service Pack 1 Hot Patch 1, update to 2014 R2 Service Pack 1 Hot Patch 1 or later to resolve the issue. As a temporary workaround, consider restricting the length of username and password inputs to prevent exploitation.

Exploit

Fix

RCE

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-01287
CVE-2016-5762

Affected Products

Novell Groupwise