Novell Groupwise Windows Client API Unauthorized Email Access Vulnerability
BID:18716
CVE-2006-3268 |Info
Novell Groupwise Windows Client API Unauthorized Email Access Vulnerability
| Bugtraq ID: | 18716 |
| Class: | Access Validation Error |
| CVE: |
CVE-2006-3268 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 29 2006 12:00AM |
| Updated: | Jun 29 2006 05:19PM |
| Credit: | The vendor disclosed this issue. |
| Vulnerable: |
Novell Groupwise 32-bit Client 0 Novell Groupwise 7.0 Novell Groupwise 6.5.4 Novell Groupwise 6.5.3 Novell Groupwise 6.5.2 Novell Groupwise 6.5 SP5 Novell Groupwise 6.5 SP4 Novell Groupwise 6.5 SP3 Novell Groupwise 6.5 SP2 Novell Groupwise 6.5 SP1 Novell Groupwise 6.5 Novell Groupwise 6.0 SP4 Novell Groupwise 6.0 SP3 Novell Groupwise 6.0 SP2 Novell Groupwise 6.0 SP1 Novell Groupwise 6.0 Novell Groupwise 5.5 Novell Groupwise 5.2 |
| Not Vulnerable: | |
Discussion
Novell Groupwise Windows Client API Unauthorized Email Access Vulnerability
The Groupwise Windows Client API has an unspecified vulnerability that allows an attacker to bypass security controls and gain unauthorized access to email stores.
An attacker can exploit this issue to access email of another user in the same authenticated post office.
The Groupwise Windows Client API has an unspecified vulnerability that allows an attacker to bypass security controls and gain unauthorized access to email stores.
An attacker can exploit this issue to access email of another user in the same authenticated post office.
Exploit / POC
Novell Groupwise Windows Client API Unauthorized Email Access Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Novell Groupwise Windows Client API Unauthorized Email Access Vulnerability
Solution:
Novell has released updated versions of the affected software to address this issue.
Novell Groupwise 6.5 SP3
Novell Groupwise 6.5 SP2
Novell Groupwise 6.5
Novell Groupwise 6.5 SP5
Novell Groupwise 6.5 SP1
Novell Groupwise 6.5 SP4
Novell Groupwise 7.0
Solution:
Novell has released updated versions of the affected software to address this issue.
Novell Groupwise 6.5 SP3
-
Novell gw656up1lnxm.tar.gz
SP6 Client Update 1
http://support.novell.com/filefinder/16963/index.html
Novell Groupwise 6.5 SP2
-
Novell gw656up1lnxm.tar.gz
SP6 Client Update 1
http://support.novell.com/filefinder/16963/index.html
Novell Groupwise 6.5
-
Novell gw656up1lnxm.tar.gz
SP6 Client Update 1
http://support.novell.com/filefinder/16963/index.html
Novell Groupwise 6.5 SP5
-
Novell gw656up1lnxm.tar.gz
SP6 Client Update 1
http://support.novell.com/filefinder/16963/index.html
Novell Groupwise 6.5 SP1
-
Novell gw656up1lnxm.tar.gz
SP6 Client Update 1
http://support.novell.com/filefinder/16963/index.html
Novell Groupwise 6.5 SP4
-
Novell gw656up1lnxm.tar.gz
SP6 Client Update 1
http://support.novell.com/filefinder/16963/index.html
Novell Groupwise 7.0
-
Novell Novell Groupwise 7 SP1
http://support.novell.com/filefinder/20641/index.html
References
Novell Groupwise Windows Client API Unauthorized Email Access Vulnerability
References:
References:
- eDirectory Product Homepage (Novell)