Novell GroupWise VCALENDAR Multiple Vulnerabilities
Last Update Date:
27 Jan 2011 16:05
Release Date:
27 Jan 2011
7249
Views
RISK: High Risk
TYPE: Servers - Other Servers
A vulnerability has been identified in Novell GroupWise, which could be exploited by remote attackers to take complete control of a vulnerable system. This issue is caused by a buffer overflow error in the "gwwww1.dll" module when processing the "TZID" or "REQUEST-STATUS" variables within VCALENDAR data, which could be exploited to execute arbitrary code with SYSTEM privileges.
Impact
- Remote Code Execution
System / Technologies affected
- Novell GroupWise 8.x
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Upgrade to Novell GroupWise version 8.02 HP 2 (Hot Patch 2) or later.
Vulnerability Identifier
Source
Related Link
Share with