In association with heise online

2 February 2009, 18:56

Security Updates for Novell GroupWise

Novell has released updates for GroupWise to close a number of vulnerabilities. One critical issue is a buffer overflow in the GroupWise Internet Agent (GWIA), which can be manipulated to allow the injection and execution of code. Other updates close issues with cross-site scripting, Cross-Site Request Forgery and Script Insertion gaps.

The vulnerabilities affect GroupWise 6.5x, GroupWise 7.0, 7.01, 7.02x, 7.03, 7.03 HP1a and GroupWise 8.0. Groupwise 7.x users should apply 7.03 Hot Patch 2 (HP2), and Groupwise 8.x users should apply 8.0 Hot Patch 1 (HP1). Version 6.5x is, however, no longer supported, so an upgrade to Groupwise 7.03 HP2 or 8.0 HP1 is recommended.

See also:

(djwm)

  • Share this article
  • Twitter
  • Facebook
  • digg this
  • submit to slashdot
  • post to delicious
  • StumbleUpon
  • submit to reddit






The H open source

The H Security

The H Internet Toolkit