Novell GroupWise Messenger Client Buffer Overflow Vulnerabilities
BID:29602
Info
Novell GroupWise Messenger Client Buffer Overflow Vulnerabilities
| Bugtraq ID: | 29602 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2008-2703 CVE-2008-2704 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 05 2008 12:00AM |
| Updated: | Jul 03 2008 12:40AM |
| Credit: | Franciso Amato of Infobyte Security Research |
| Vulnerable: |
Novell GroupWise Messenger 2.0.3 Novell GroupWise Messenger 2.0 |
| Not Vulnerable: |
Novell GroupWise Messenger 2.0.3 HP1 |
Discussion
Novell GroupWise Messenger Client Buffer Overflow Vulnerabilities
Novell GroupWise Messenger is prone to two buffer-overflow vulnerabilities because it fails to adequately bounds-check user-supplied data before copying it to an insufficiently sized buffer.
Attackers can exploit these issues to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
Versions prior to Novell GroupWise Messenger 2.0.3 HP1 are vulnerable.
Novell GroupWise Messenger is prone to two buffer-overflow vulnerabilities because it fails to adequately bounds-check user-supplied data before copying it to an insufficiently sized buffer.
Attackers can exploit these issues to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
Versions prior to Novell GroupWise Messenger 2.0.3 HP1 are vulnerable.
Exploit / POC
Novell GroupWise Messenger Client Buffer Overflow Vulnerabilities
The following proof-of-concept code is available:
The following proof-of-concept code is available:
Solution / Fix
Novell GroupWise Messenger Client Buffer Overflow Vulnerabilities
Solution:
Novell has released a hot patch to address the issues. Please see the references for more information.
Solution:
Novell has released a hot patch to address the issues. Please see the references for more information.
References
Novell GroupWise Messenger Client Buffer Overflow Vulnerabilities
References:
References:
- GroupWise Messenger 2.0.3 Hot Patch 1 Client for Windows - US and Multi (Novell)
- Novell GroupWise Homepage (Novell)
- Novell GroupWise Messenger Client (GWIM) Remote Stack Overflow (Infobyte Security Research)
- Novell Homepage (Novell)
- 5026700 GroupWise Messenger 2.0.3 Hot Patch 1 Client for Windows - US and Multi (Novell)