First published: Wed Sep 19 2012(Updated: )
The iCalendar component in gwwww1.dll in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before Support Pack 3 allows remote attackers to cause a denial of service (out-of-bounds read and daemon crash) via a crafted date-time string in a .ics attachment.
Credit: PSIRT-CNA@flexerasoftware.com
Affected Software | Affected Version | How to fix |
---|---|---|
Micro Focus GroupWise | <=8.00 | |
Micro Focus GroupWise | =8.0 | |
Micro Focus GroupWise | =8.00-hp1 | |
Micro Focus GroupWise | =8.00-hp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-3827 is classified as a denial of service vulnerability, allowing remote attackers to crash the GroupWise Internet Agent.
To mitigate CVE-2011-3827, update Novell GroupWise to at least Support Pack 3 or apply relevant patches.
The vulnerability affects the iCalendar component in the gwwww1.dll of Novell GroupWise 8.0 prior to Support Pack 3.
CVE-2011-3827 can be exploited by sending a malicious .ics attachment with a crafted date-time string.
Yes, user intervention is required as the vulnerability is triggered when the crafted .ics attachment is opened.