In association with heise online

25 May 2009, 10:21

Novell fixes critical vulnerabilities in GroupWise

  • Twitter
  • Facebook
  • submit to slashdot
  • StumbleUpon
  • submit to reddit

Novell has released updates for GroupWise 7.x and 8.x to fix six security vulnerabilities. Two of the vulnerabilities relate to buffer overflows in the GroupWise Internet Agent (GWIA) when reading e-mails via SMTP and when processing certain SMTP requests. Attackers are reportedly able to exploit the bugs remotely without authentication to inject and execute code with SYSTEM privileges.

The other vulnerabilities concern WebAccess, and permit attackers to gain access to an e-mail account using XSS or vulnerabilities in session management access. According to a security advisory, the bugs are present in Novell GroupWise 7.03 HP2 and earlier and GroupWise 8.0.0 HP1 and earlier. The vulnerabilities are fixed in GroupWise 7.03 Hot Patch 3 (HP3) and GroupWise 8.0 Hot Patch 2 (HP2).

See also:

(djwm)

Print Version | Send by email | Permalink: http://h-online.com/-741721
 


  • July's Community Calendar





The H Open

The H Security

The H Developer

The H Internet Toolkit