Novell Messenger Server Memory Information Disclosure Vulnerability
BID:50443
Info
Novell Messenger Server Memory Information Disclosure Vulnerability
| Bugtraq ID: | 50443 |
| Class: | Design Error |
| CVE: |
CVE-2011-3179 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 31 2011 12:00AM |
| Updated: | Oct 31 2011 12:00AM |
| Credit: | Luigi Auriemma |
| Vulnerable: |
Novell Messenger 2.2.0 Novell Messenger 2.1 Novell GroupWise Messenger 2.0.3 Novell GroupWise Messenger 2.0 |
| Not Vulnerable: |
Novell Messenger 2.2.1 |
Discussion
Novell Messenger Server Memory Information Disclosure Vulnerability
Novell Messenger Server Process is prone to an information-disclosure vulnerability that lets attackers retrieve contents of arbitrary memory locations.
An attacker can exploit this vulnerability to retrieve certain files from the vulnerable computer in the context of the webserver process. Information obtained may aid in further attacks.
Novell Messenger Server Process is prone to an information-disclosure vulnerability that lets attackers retrieve contents of arbitrary memory locations.
An attacker can exploit this vulnerability to retrieve certain files from the vulnerable computer in the context of the webserver process. Information obtained may aid in further attacks.
Exploit / POC
Novell Messenger Server Memory Information Disclosure Vulnerability
Attackers can exploit this vulnerability via a browser.
Attackers can exploit this vulnerability via a browser.
Solution / Fix
Novell Messenger Server Memory Information Disclosure Vulnerability
Solution:
Vendor updates are available. Please see the references for details.
Solution:
Vendor updates are available. Please see the references for details.
References
Novell Messenger Server Memory Information Disclosure Vulnerability
References:
References: