Novell GroupWise Internet Agent CVE-2012-0417 Remote Integer Overflow Vulnerability
BID:55731
Info
Novell GroupWise Internet Agent CVE-2012-0417 Remote Integer Overflow Vulnerability
| Bugtraq ID: | 55731 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2012-0417 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 28 2012 12:00AM |
| Updated: | Sep 28 2012 12:00AM |
| Credit: | Francis Provencher working with TippingPoint's Zero Day Initiative |
| Vulnerable: |
Novell Groupwise 2012 0 Novell Groupwise 8.02 HP3 Novell Groupwise 8.02 HP2 Novell Groupwise 8.02 HP1 Novell Groupwise 8.02 Novell Groupwise 8.0 SP2 Novell Groupwise 8.0 SP1 Novell Groupwise 8.0 HP3 Novell Groupwise 8.0 HP2 Novell Groupwise 8.0 HP1 Novell Groupwise 8.0 |
| Not Vulnerable: | |
Discussion
Novell GroupWise Internet Agent CVE-2012-0417 Remote Integer Overflow Vulnerability
Novell GroupWise Internet Agent is prone to a remote integer-overflow vulnerability that may cause a heap-based buffer-overflow.
An attacker can exploit this issue to execute arbitrary malicious code in the context of the affected application. Failed exploit attempts will likely crash the application.
The following versions are vulnerable:
Versions prior to GroupWise 8.0 SP3
Versions prior to GroupWise 2012 Support Pack 1
Novell GroupWise Internet Agent is prone to a remote integer-overflow vulnerability that may cause a heap-based buffer-overflow.
An attacker can exploit this issue to execute arbitrary malicious code in the context of the affected application. Failed exploit attempts will likely crash the application.
The following versions are vulnerable:
Versions prior to GroupWise 8.0 SP3
Versions prior to GroupWise 2012 Support Pack 1
Exploit / POC
Novell GroupWise Internet Agent CVE-2012-0417 Remote Integer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Novell GroupWise Internet Agent CVE-2012-0417 Remote Integer Overflow Vulnerability
References:
References:
- GroupWise 8.0 SP3 Hot Patch 1 Full Release for Windows and NLM EN (Novell)
- Novell GroupWise HomePage (Novell)
- Security Vulnerability: GroupWise Internet Agent (GWIA) integer overflow vulnera (Novell)
- ZDI-12-196 : Novell Groupwise GWIA ber_get_stringa Remote Code Execution Vulnera (TippingPoint Zero Day Initiative)