CVE-2005-2176: Medium severity Novell Netmail vulnerability
Published Jul 9, 2005
·Updated
Novell NetMail automatically processes HTML in an attachment without prompting the user to save or open it, which makes it easier for remote attackers to conduct web-based attacks and steal cookies.
Affected Software
19 affected components
Novell Netmail=3.5.2-c
Novell Netmail=3.1
Novell Netmail=3.10-f
Novell Netmail=3.0.1
Novell Netmail=3.10-g
Novell Netmail=3.10-e
Novell Netmail=3.5.2-b
Novell Netmail=3.5.2-c1
Novell Netmail=3.10-h
Novell Netmail=3.5.2-a
Novell Netmail=3.10-b
Novell Netmail=3.0.3a-a
Novell Netmail=3.0.3a-b
Novell Netmail=3.5.2-e-ftfl
Novell Netmail=3.1-f
Novell Netmail=3.10
Novell Netmail=3.10-c
Novell Netmail=3.10-a
Novell Netmail=3.10-d
Event History
Jul 9, 2005
CVE Published
04:00 AM
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-2176?
CVE-2005-2176 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2005-2176?
To fix CVE-2005-2176, update to the latest version of Novell NetMail that addresses this vulnerability.
3
What software is affected by CVE-2005-2176?
CVE-2005-2176 affects multiple versions of Novell NetMail including 3.1, 3.5.2, and 3.10.
4
Can CVE-2005-2176 allow remote attacks?
Yes, CVE-2005-2176 can enable remote attackers to conduct web-based attacks without user interaction.
5
What type of attack can CVE-2005-2176 be used for?
CVE-2005-2176 can be exploited to steal cookies and perform unauthorized actions on behalf of users.