CVE-2010-4713: Critical severity novell groupwise vulnerability
Published Jan 31, 2011
·Updated
Integer signedness error in gwia.exe in GroupWise Internet Agent (GWIA) in Novell GroupWise before 8.02HP allows remote attackers to execute arbitrary code via a signed integer value in the Content-Type header.
Affected Software
32 affected components
Novell GroupWise<=8.0.2
Novell GroupWise=4.1
Novell GroupWise=4.1a
Novell GroupWise=5.0
Novell GroupWise=5.1
Novell GroupWise=5.2
Novell GroupWise=5.5
Novell GroupWise=5.5
Novell GroupWise=5.57e
Novell GroupWise=6.0
Novell GroupWise=6.0-sp1
Novell GroupWise=6.0-sp5
Novell GroupWise=6.0.1-sp1
Novell GroupWise=6.5
Novell GroupWise=6.5-sp1
Novell GroupWise=6.5-sp2
Novell GroupWise=6.5-sp3
Novell GroupWise=6.5-sp4
Novell GroupWise=6.5-sp5
Novell GroupWise=6.5-sp6
Novell GroupWise=6.5.2
Novell GroupWise=6.5.3
Novell GroupWise=6.5.4
Novell GroupWise=6.5.6
Novell GroupWise=6.5.7
Novell GroupWise=7.0
Novell GroupWise=7.0.1
Novell GroupWise=7.0.2
Novell GroupWise=7.0.3
Novell GroupWise=7.0.4
Novell GroupWise=8.0
Novell GroupWise=8.0.1
Event History
Jan 31, 2011
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-4713?
CVE-2010-4713 is rated as high severity due to its potential to allow remote code execution.
2
How do I fix CVE-2010-4713?
The recommended fix for CVE-2010-4713 is to upgrade to Novell GroupWise version 8.02HP or later.
3
Which versions of Novell GroupWise are affected by CVE-2010-4713?
CVE-2010-4713 affects Novell GroupWise versions up to 8.0.2, including 6.0, 6.5, and all 7.x versions.
4
What kind of vulnerability is CVE-2010-4713?
CVE-2010-4713 is an integer signedness error that can be exploited through the Content-Type header.
5
Can CVE-2010-4713 be exploited remotely?
Yes, CVE-2010-4713 can be exploited remotely by attackers sending specially crafted requests.