Novell GroupWise Internet Agent SMTP RCPT Command Remote Buffer Overflow Vulnerability
BID:33560
Info
Novell GroupWise Internet Agent SMTP RCPT Command Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 33560 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2009-0410 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 30 2009 12:00AM |
| Updated: | Feb 06 2009 07:48PM |
| Credit: | Nick DeBaggis working with TippingPoint's Zero Day Initiative |
| Vulnerable: |
Novell Groupwise 7.0 Novell Groupwise 6.5.7 Novell Groupwise 6.5.6 Novell Groupwise 6.5.4 Novell Groupwise 6.5.3 Novell Groupwise 6.5.2 Novell Groupwise 6.5 SP6 Update 1 Novell Groupwise 6.5 SP6 Novell Groupwise 6.5 SP5 Novell Groupwise 6.5 SP4 Novell Groupwise 6.5 SP3 Novell Groupwise 6.5 SP2 Novell Groupwise 6.5 SP1 Novell Groupwise 6.5 Novell Groupwise 6.5 Novell Groupwise 8.0 Novell Groupwise 7.03HP1a Novell Groupwise 7.03 Novell Groupwise 7.02x Novell Groupwise 7.01 Novell Groupwise 7.0.0 SP3 Novell Groupwise 7.0.0 SP2 Novell Groupwise 7.0.0 SP1 Novell Groupwise 6.5 SP6 Update 3 |
| Not Vulnerable: |
Novell Groupwise 8.0 HP1 Novell Groupwise 7.03 HP2 |
Discussion
Novell GroupWise Internet Agent SMTP RCPT Command Remote Buffer Overflow Vulnerability
Novell GroupWise Internet Agent is prone to a remote buffer-overflow vulnerability.
An attacker can exploit this issue to execute arbitrary code within the context of the affected application, possibly with root or SYSTEM-level privileges. Failed exploit attempts will result in a denial-of-service condition.
Novell GroupWise Internet Agent is prone to a remote buffer-overflow vulnerability.
An attacker can exploit this issue to execute arbitrary code within the context of the affected application, possibly with root or SYSTEM-level privileges. Failed exploit attempts will result in a denial-of-service condition.
Exploit / POC
Novell GroupWise Internet Agent SMTP RCPT Command Remote Buffer Overflow Vulnerability
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following proof of concept is available:
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following proof of concept is available:
Solution / Fix
Novell GroupWise Internet Agent SMTP RCPT Command Remote Buffer Overflow Vulnerability
Solution:
Vendor fixes are available; please see the references for more information.
Solution:
Vendor fixes are available; please see the references for more information.
References
Novell GroupWise Internet Agent SMTP RCPT Command Remote Buffer Overflow Vulnerability
References:
References: