CVE-2011-3827: Buffer Overflow
The iCalendar component in gwwww1.dll in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before Support Pack 3 allows remote attackers to cause a denial of service (out-of-bounds read and daemon crash) via a crafted date-time string in a .ics attachment.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-3827?
CVE-2011-3827 is classified as a denial of service vulnerability, allowing remote attackers to crash the GroupWise Internet Agent.
How do I fix CVE-2011-3827?
To mitigate CVE-2011-3827, update Novell GroupWise to at least Support Pack 3 or apply relevant patches.
What components are affected by CVE-2011-3827?
The vulnerability affects the iCalendar component in the gwwww1.dll of Novell GroupWise 8.0 prior to Support Pack 3.
What types of attacks can exploit CVE-2011-3827?
CVE-2011-3827 can be exploited by sending a malicious .ics attachment with a crafted date-time string.
Is user intervention needed to exploit CVE-2011-3827?
Yes, user intervention is required as the vulnerability is triggered when the crafted .ics attachment is opened.