Novell Fixes Critical Vulnerabilities In Groupwise


Recommended Posts

25 May 2009, 11:21

Novell fixes critical vulnerabilities in GroupWise

"Novell has released updates for GroupWise 7.x and 8.x to fix six security vulnerabilities. Two of the vulnerabilities relate to buffer overflows in the GroupWise Internet Agent (GWIA) when reading e-mails via SMTP and when processing certain SMTP requests. Attackers are reportedly able to exploit the bugs remotely without authentication to inject and execute code with SYSTEM privileges.

The other vulnerabilities concern WebAccess, and permit attackers to gain access to an e-mail account using XSS or vulnerabilities in session management access. According to a security advisory, the bugs are present in Novell GroupWise 7.03 HP2 and earlier and GroupWise 8.0.0 HP1 and earlier. The vulnerabilities are fixed in GroupWise 7.03 Hot Patch 3 (HP3) and GroupWise 8.0 Hot Patch 2 (HP2)."

See also:

Novell GroupWise Buffer Overflow and Cross Site Scripting Vulnerabilities, Advisory from VUPEN

(djwm)

Heise security - http://www.h-online.com/security/Novell-fi...e--/news/113365

Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...