Novell GroupWise 'TZNAME' Variable Parsing Remote Code Execution Vulnerability
BID:49774
Info
Novell GroupWise 'TZNAME' Variable Parsing Remote Code Execution Vulnerability
| Bugtraq ID: | 49774 |
| Class: | Unknown |
| CVE: |
CVE-2011-0333 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 26 2011 12:00AM |
| Updated: | Sep 28 2011 03:50PM |
| Credit: | Carsten Eiram of Secunia Research and an anonymous researcher working with Verisign's iDefense Labs |
| Vulnerable: |
Novell GroupWise Internet Agent 8.0 Novell Groupwise 8.0 HP2 Novell Groupwise 8.0 HP1 Novell Groupwise 8.0 |
| Not Vulnerable: |
Novell Groupwise 8.0 HP3 |
Discussion
Novell GroupWise 'TZNAME' Variable Parsing Remote Code Execution Vulnerability
The Novell GroupWise Internet Agent is prone to a remote code-execution vulnerability.
Attackers could exploit this issue to execute arbitrary code with SYSTEM-level privileges. Successful exploits will completely compromise affected computers. Failed exploit attempts will result in a denial-of-service condition.
The Novell GroupWise Internet Agent is prone to a remote code-execution vulnerability.
Attackers could exploit this issue to execute arbitrary code with SYSTEM-level privileges. Successful exploits will completely compromise affected computers. Failed exploit attempts will result in a denial-of-service condition.
Exploit / POC
Novell GroupWise 'TZNAME' Variable Parsing Remote Code Execution Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Novell GroupWise 'TZNAME' Variable Parsing Remote Code Execution Vulnerability
Solution:
Vendor updates are available. Please see the referenced advisory for more information.
Solution:
Vendor updates are available. Please see the referenced advisory for more information.
References
Novell GroupWise 'TZNAME' Variable Parsing Remote Code Execution Vulnerability
References:
References:
- Novell GroupWise Homepage (Novell)
- Security Vulnerability - GroupWise 8 Internet Agent TZNAME (VCALENDAR) Variable (Novell)
- VUPEN Security Research - Novell GroupWise "TZNAME" Remote Buffer Overflow Vulne (VUPEN Security Research
) - Secunia Research: Novell GroupWise Internet Agent 'TZNAME' Parsing Vulnerability (Secunia)