First published: Fri Jun 13 2008(Updated: )
Multiple stack-based buffer overflows in Novell GroupWise Messenger (GWIM) Client before 2.0.3 HP1 for Windows allow remote attackers to execute arbitrary code via "spoofed server responses" that contain a long string after the NM_A_SZ_TRANSACTION_ID field name.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Novell GroupWise Messenger | =2.0.2 | |
Novell GroupWise Messenger | =2.0.3 | |
Novell GroupWise Messenger | =2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-2703 has a high severity rating due to its potential for remote code execution.
To mitigate CVE-2008-2703, upgrade to Novell GroupWise Messenger version 2.0.3 HP1 or later.
CVE-2008-2703 affects Novell GroupWise Messenger versions 2.0, 2.0.2, and 2.0.3 before HP1.
CVE-2008-2703 exploits stack-based buffer overflows caused by spoofed server responses.
Any user running vulnerable versions of Novell GroupWise Messenger on their Windows system can be impacted by CVE-2008-2703.