CVE-2010-4325: Buffer Overflow
Published Jan 28, 2011
·Updated
Buffer overflow in gwwww1.dll in GroupWise Internet Agent (GWIA) in Novell GroupWise before 8.02HP2 allows remote attackers to execute arbitrary code via a crafted TZID variable in a VCALENDAR message.
Affected Software
32 affected components
Novell GroupWise<=8.0.2
Novell GroupWise=4.1
Novell GroupWise=4.1a
Novell GroupWise=5.0
Novell GroupWise=5.1
Novell GroupWise=5.2
Novell GroupWise=5.5
Novell GroupWise=5.5
Novell GroupWise=5.57e
Novell GroupWise=6.0
Novell GroupWise=6.0-sp1
Novell GroupWise=6.0-sp5
Novell GroupWise=6.0.1-sp1
Novell GroupWise=6.5
Novell GroupWise=6.5-sp1
Novell GroupWise=6.5-sp2
Novell GroupWise=6.5-sp3
Novell GroupWise=6.5-sp4
Novell GroupWise=6.5-sp5
Novell GroupWise=6.5-sp6
Novell GroupWise=6.5.2
Novell GroupWise=6.5.3
Novell GroupWise=6.5.4
Novell GroupWise=6.5.6
Novell GroupWise=6.5.7
Novell GroupWise=7.0
Novell GroupWise=7.0.1
Novell GroupWise=7.0.2
Novell GroupWise=7.0.3
Novell GroupWise=7.0.4
Novell GroupWise=8.0
Novell GroupWise=8.0.1
Event History
Jan 28, 2011
CVE Published
via MITRE·08:29 PM
Data Sourced
via MITRE·08:29 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-4325?
CVE-2010-4325 has a high severity rating due to the potential for remote code execution.
2
How do I fix CVE-2010-4325?
To fix CVE-2010-4325, update to Novell GroupWise version 8.02HP2 or later.
3
Which versions of GroupWise are affected by CVE-2010-4325?
CVE-2010-4325 affects Novell GroupWise versions 4.1 to 8.0.2, including various specific service packs.
4
What are the consequences of exploiting CVE-2010-4325?
Exploiting CVE-2010-4325 can lead to arbitrary code execution on the affected system.
5
Is there a workaround for CVE-2010-4325 while waiting for a patch?
A recommended workaround is to restrict access to the GroupWise Internet Agent until the software is updated.