Novell GroupWise 5.5 Enhancement Pack DoS Vulnerability
BID:972
Info
Novell GroupWise 5.5 Enhancement Pack DoS Vulnerability
| Bugtraq ID: | 972 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Feb 07 2000 12:00AM |
| Updated: | Feb 07 2000 12:00AM |
| Credit: | Posted to Bugtraq by Adam Gray <[email protected]> on February 7, 2000. |
| Vulnerable: |
Novell Groupwise Enhancement Pack 5.5 |
| Not Vulnerable: | |
Discussion
Novell GroupWise 5.5 Enhancement Pack DoS Vulnerability
By requesting a long URL from a Novell Groupwise 5.5 webserver with the Enhancement Pack installed, it is possible to cause the server to abend, the Java.nlm to take up all available CPU resource, or to stop the post office service. The server will need to be rebooted to restore normal operation.
By requesting a long URL from a Novell Groupwise 5.5 webserver with the Enhancement Pack installed, it is possible to cause the server to abend, the Java.nlm to take up all available CPU resource, or to stop the post office service. The server will need to be rebooted to restore normal operation.
Exploit / POC
Novell GroupWise 5.5 Enhancement Pack DoS Vulnerability
http ://target/servlet/long string of 200+ characters
http ://target/servlet/long string of 200+ characters
Solution / Fix
Novell GroupWise 5.5 Enhancement Pack DoS Vulnerability
Solution:
GroupWise Enhancement Pack 5.5 sp1 has been released which addresses this problem. To obtain it, contact Novell Technical Support.
Solution:
GroupWise Enhancement Pack 5.5 sp1 has been released which addresses this problem. To obtain it, contact Novell Technical Support.
References
Novell GroupWise 5.5 Enhancement Pack DoS Vulnerability
References:
References:
- Groupwise 5.5 Tech Support Page (Novell)