CVE-2008-2704: Input Validation
Published Jun 13, 2008
·Updated
Novell GroupWise Messenger (GWIM) before 2.0.3 Hot Patch 1 allows remote attackers to cause a denial of service (crash) via a long user ID, possibly involving a popup alert. NOTE: it is not clear whether this issue crosses privilege boundaries.
Affected Software
4 affected components
Novell GroupWise Messenger=2.0.2
Novell GroupWise Messenger=1.0.6
Novell GroupWise Messenger=2.0.3
Novell GroupWise Messenger=2.0
Remediation
Patch Available
Event History
Jun 13, 2008
CVE Published
via MITRE·07:19 PM
Data Sourced
via MITRE·07:19 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-2704?
CVE-2008-2704 has a severity rating that indicates it can cause a denial of service by crashing the application.
2
How do I fix CVE-2008-2704?
To fix CVE-2008-2704, upgrade to Novell GroupWise Messenger version 2.0.3 Hot Patch 1 or later.
3
What software versions are affected by CVE-2008-2704?
CVE-2008-2704 affects Novell GroupWise Messenger versions 1.0.6, 2.0, 2.0.2, and 2.0.3.
4
Can CVE-2008-2704 be exploited remotely?
Yes, CVE-2008-2704 can be exploited remotely by sending a long user ID.
5
Is there a privilege boundary concern with CVE-2008-2704?
It is unclear whether CVE-2008-2704 crosses privilege boundaries during exploitation.