Novell GroupWise Internet Agent Buffer Overflow Vulnerability
BID:5313
Info
Novell GroupWise Internet Agent Buffer Overflow Vulnerability
| Bugtraq ID: | 5313 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 25 2002 12:00AM |
| Updated: | Jul 25 2002 12:00AM |
| Credit: | Credited to Marco van Berkum <[email protected]>. |
| Vulnerable: |
Novell Groupwise 6.0 SP1 Novell Groupwise 6.0 |
| Not Vulnerable: |
Novell Groupwise 6.0 SP2 |
Discussion
Novell GroupWise Internet Agent Buffer Overflow Vulnerability
A buffer overflow vulnerability has been reported in Novell GroupWise 6.0.1 with Support Pack 1. Reportedly, this vulnerability occurs in the Internet Agent, which is an MTA (Mail Transfer Agent) for Novell GroupWise.
It is possible for an attacker to cause a buffer overflow condition in the Internet Agent by supplying an overly long string and using it as an argument for the 'RCPT TO' field when composing emails. This will cause the Internet Agent to crash.
A buffer overflow vulnerability has been reported in Novell GroupWise 6.0.1 with Support Pack 1. Reportedly, this vulnerability occurs in the Internet Agent, which is an MTA (Mail Transfer Agent) for Novell GroupWise.
It is possible for an attacker to cause a buffer overflow condition in the Internet Agent by supplying an overly long string and using it as an argument for the 'RCPT TO' field when composing emails. This will cause the Internet Agent to crash.
Exploit / POC
Novell GroupWise Internet Agent Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Novell GroupWise Internet Agent Buffer Overflow Vulnerability
Solution:
The vendor has released Support Pack 2 to address this vulnerability:
Novell Groupwise 6.0
Novell Groupwise 6.0 SP1
Solution:
The vendor has released Support Pack 2 to address this vulnerability:
Novell Groupwise 6.0
-
Novell Beta Patches - GroupWise 6
http://support.novell.com/filefinder/12886/beta.html
Novell Groupwise 6.0 SP1
-
Novell Beta Patches - GroupWise 6
http://support.novell.com/filefinder/12886/beta.html
References
Novell GroupWise Internet Agent Buffer Overflow Vulnerability
References:
References:
- Novell GroupWise Homepage (Novell)