CVE-2011-2663: Buffer Overflow
Published Oct 8, 2011
·Updated
Array index error in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to execute arbitrary code via a crafted yearly RRULE variable in a VCALENDAR attachment in an e-mail message.
Affected Software
3 affected components
Novell GroupWise=8.0
Novell GroupWise=8.0-hp1
Novell GroupWise=8.0-hp2
Event History
Oct 8, 2011
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-2663?
CVE-2011-2663 is considered to be a critical vulnerability due to its potential to allow remote code execution.
2
How do I fix CVE-2011-2663?
To mitigate CVE-2011-2663, update to Novell GroupWise version 8.0 HP3 or later.
3
Which versions of Novell GroupWise are affected by CVE-2011-2663?
CVE-2011-2663 affects Novell GroupWise 8.0 before HP3 as well as 8.0 HP1 and HP2.
4
Can CVE-2011-2663 be exploited remotely?
Yes, CVE-2011-2663 can be exploited remotely through a crafted VCALENDAR attachment in an email.
5
What type of attack is possible with CVE-2011-2663?
CVE-2011-2663 allows attackers to execute arbitrary code on the target system.