Novell fixes critical vulnerabilities in GroupWise
Novell has released updates for GroupWise 7.x and 8.x to fix six security vulnerabilities. Two of the vulnerabilities relate to buffer overflows in the GroupWise Internet Agent (GWIA) when reading e-mails via SMTP and when processing certain SMTP requests. Attackers are reportedly able to exploit the bugs remotely without authentication to inject and execute code with SYSTEM privileges.
The other vulnerabilities concern WebAccess, and permit attackers to gain access to an e-mail account using XSS or vulnerabilities in session management access. According to a security advisory, the bugs are present in Novell GroupWise 7.03 HP2 and earlier and GroupWise 8.0.0 HP1 and earlier. The vulnerabilities are fixed in GroupWise 7.03 Hot Patch 3 (HP3) and GroupWise 8.0 Hot Patch 2 (HP2).
- Novell GroupWise Buffer Overflow and Cross Site Scripting Vulnerabilities, Advisory from VUPEN