CVE-2010-4712: Buffer Overflow
Published Jan 31, 2011
·Updated
Multiple stack-based buffer overflows in gwia.exe in GroupWise Internet Agent (GWIA) in Novell GroupWise before 8.02HP allow remote attackers to execute arbitrary code via a Content-Type header containing (1) multiple items separated by ; (semicolon) characters or (2) crafted string data.
Affected Software
32 affected components
Novell GroupWise=7.0.4
Novell GroupWise=6.5-sp5
Novell GroupWise=6.0
Novell GroupWise=7.0
Novell GroupWise=7.0.1
Novell GroupWise=5.5
Novell GroupWise=7.0.2
Novell GroupWise=6.5.6
Novell GroupWise=6.5.3
Novell GroupWise<=8.0.2
Novell GroupWise=8.0.1
Novell GroupWise=8.0
Novell GroupWise=6.5-sp1
Novell GroupWise=5.2
Novell GroupWise=6.5.4
Novell GroupWise=6.0-sp1
Novell GroupWise=6.5-sp6
Novell GroupWise=6.5-sp4
Novell GroupWise=6.0-sp5
Novell GroupWise=4.1
Novell GroupWise=5.1
Novell GroupWise=6.5-sp3
Novell GroupWise=6.0.1-sp1
Novell GroupWise=7.0.3
Novell GroupWise=5.5
Novell GroupWise=6.5
Novell GroupWise=5.0
Novell GroupWise=4.1a
Novell GroupWise=6.5.2
Novell GroupWise=6.5-sp2
Novell GroupWise=5.57e
Novell GroupWise=6.5.7
Event History
Jan 31, 2011
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-4712?
CVE-2010-4712 has a high severity due to the potential for remote code execution.
2
How do I fix CVE-2010-4712?
To fix CVE-2010-4712, update to Novell GroupWise version 8.02HP or later.
3
What types of attacks are possible with CVE-2010-4712?
CVE-2010-4712 allows remote attackers to execute arbitrary code through crafted Content-Type headers.
4
Which versions of Novell GroupWise are affected by CVE-2010-4712?
CVE-2010-4712 affects multiple versions of Novell GroupWise, including versions prior to 8.02HP.
5
What component of Novell GroupWise is vulnerable in CVE-2010-4712?
The vulnerable component in CVE-2010-4712 is gwia.exe in the GroupWise Internet Agent.