Peaches Posted May 26, 2009 Report Share Posted May 26, 2009 25 May 2009, 11:21Novell fixes critical vulnerabilities in GroupWise "Novell has released updates for GroupWise 7.x and 8.x to fix six security vulnerabilities. Two of the vulnerabilities relate to buffer overflows in the GroupWise Internet Agent (GWIA) when reading e-mails via SMTP and when processing certain SMTP requests. Attackers are reportedly able to exploit the bugs remotely without authentication to inject and execute code with SYSTEM privileges.The other vulnerabilities concern WebAccess, and permit attackers to gain access to an e-mail account using XSS or vulnerabilities in session management access. According to a security advisory, the bugs are present in Novell GroupWise 7.03 HP2 and earlier and GroupWise 8.0.0 HP1 and earlier. The vulnerabilities are fixed in GroupWise 7.03 Hot Patch 3 (HP3) and GroupWise 8.0 Hot Patch 2 (HP2)."See also:Novell GroupWise Buffer Overflow and Cross Site Scripting Vulnerabilities, Advisory from VUPEN(djwm) Heise security - http://www.h-online.com/security/Novell-fi...e--/news/113365 Quote Link to post Share on other sites
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.