CVE-2009-0410: Buffer Overflow
Published Feb 3, 2009
·Updated
Off-by-one error in the SMTP daemon in GroupWise Internet Agent (GWIA) in Novell GroupWise 6.5x, 7.0, 7.01, 7.02, 7.03, 7.03HP1a, and 8.0 allows remote attackers to execute arbitrary code via a long e-mail address in a malformed RCPT command, leading to a buffer overflow.
Affected Software
7 affected components
Novell GroupWise=6.5
Novell GroupWise=7.0
Novell GroupWise=7.01
Novell GroupWise=7.02x
Novell GroupWise=7.03
Novell GroupWise=7.03-hp1a
Novell GroupWise=8.0
Remediation
Patch Available
Patch Available
Event History
Feb 3, 2009
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Data Sourced
via NVD·07:30 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2009-0410?
CVE-2009-0410 has a critical severity rating due to its potential for remote code execution.
2
How do I fix CVE-2009-0410?
To fix CVE-2009-0410, apply the latest patches or updates provided by Novell for affected GroupWise versions.
3
Which versions of GroupWise are affected by CVE-2009-0410?
CVE-2009-0410 affects Novell GroupWise versions 6.5, 7.0, 7.01, 7.02, 7.03, 7.03HP1a, and 8.0.
4
What type of vulnerability is CVE-2009-0410?
CVE-2009-0410 is an off-by-one error that leads to a buffer overflow vulnerability.
5
Can CVE-2009-0410 be exploited remotely?
Yes, CVE-2009-0410 can be exploited remotely through a specially crafted email.