CVE-2008-2703: Buffer Overflow
Published Jun 13, 2008
·Updated
Multiple stack-based buffer overflows in Novell GroupWise Messenger (GWIM) Client before 2.0.3 HP1 for Windows allow remote attackers to execute arbitrary code via "spoofed server responses" that contain a long string after the NMASZTRANSACTIONID field name.
Affected Software
3 affected components
Novell GroupWise Messenger=2.0
Novell GroupWise Messenger=2.0.2
Novell GroupWise Messenger=2.0.3
Remediation
Event History
Jun 13, 2008
CVE Published
via MITRE·07:19 PM
Data Sourced
via MITRE·07:19 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-2703?
CVE-2008-2703 has a high severity rating due to its potential for remote code execution.
2
How do I fix CVE-2008-2703?
To mitigate CVE-2008-2703, upgrade to Novell GroupWise Messenger version 2.0.3 HP1 or later.
3
What versions of Novell GroupWise Messenger are affected by CVE-2008-2703?
CVE-2008-2703 affects Novell GroupWise Messenger versions 2.0, 2.0.2, and 2.0.3 before HP1.
4
What type of attack does CVE-2008-2703 exploit?
CVE-2008-2703 exploits stack-based buffer overflows caused by spoofed server responses.
5
Who can be impacted by CVE-2008-2703?
Any user running vulnerable versions of Novell GroupWise Messenger on their Windows system can be impacted by CVE-2008-2703.