CVE-2011-2662: Critical severity Novell GroupWise vulnerability
Published Oct 8, 2011
·Updated
Integer signedness error in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to execute arbitrary code via a negative BYWEEKNO property in a weekly RRULE variable in a VCALENDAR attachment in an e-mail message.
Affected Software
3 affected components
Novell GroupWise=8.0-hp1
Novell GroupWise=8.0
Novell GroupWise=8.0-hp2
Event History
Oct 8, 2011
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-2662?
CVE-2011-2662 is considered a high severity vulnerability due to its potential to allow remote code execution.
2
How do I fix CVE-2011-2662?
To mitigate CVE-2011-2662, it is recommended to apply the latest patches provided by Novell for GroupWise.
3
What systems are affected by CVE-2011-2662?
CVE-2011-2662 affects Novell GroupWise versions 8.0 before HP3, including HP1 and HP2.
4
What type of attack does CVE-2011-2662 enable?
CVE-2011-2662 allows attackers to execute arbitrary code via crafted email attachments.
5
Is CVE-2011-2662 remotely exploitable?
Yes, CVE-2011-2662 can be exploited remotely by sending a specially crafted email.