Skip to main content

Novell GroupWise VCALENDAR Multiple Vulnerabilities

Last Update Date: 27 Jan 2011 16:05 Release Date: 27 Jan 2011 6143 Views

RISK: High Risk

TYPE: Servers - Other Servers

TYPE: Other Servers

A vulnerability has been identified in Novell GroupWise, which could be exploited by remote attackers to take complete control of a vulnerable system. This issue is caused by a buffer overflow error in the "gwwww1.dll" module when processing the "TZID" or "REQUEST-STATUS" variables within VCALENDAR data, which could be exploited to execute arbitrary code with SYSTEM privileges.


Impact

  • Remote Code Execution

System / Technologies affected

  • Novell GroupWise 8.x

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Upgrade to Novell GroupWise version 8.02 HP 2 (Hot Patch 2) or later.

Vulnerability Identifier


Source


Related Link