CVE-2012-0271: Buffer Overflow
Integer overflow in the WebConsole component in gwia.exe in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before 8.0.3 HP1 and 2012 before SP1 might allow remote attackers to execute arbitrary code via a crafted request that triggers a heap-based buffer overflow, as demonstrated by a request with -1 in the Content-Length HTTP header.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-0271?
CVE-2012-0271 has a high severity rating due to its potential to allow remote code execution via a specially crafted request.
How do I fix CVE-2012-0271?
To fix CVE-2012-0271, upgrade to Novell GroupWise version 8.0.3 HP1 or later, or the 2012 version with Service Pack 1.
What systems are affected by CVE-2012-0271?
CVE-2012-0271 affects Novell GroupWise versions 8.0, 8.01, 8.02, and 2012 before Service Pack 1, along with several other versions listed in the advisory.
What type of attack can exploit CVE-2012-0271?
CVE-2012-0271 can be exploited through a crafted request that triggers a heap-based buffer overflow.
Is CVE-2012-0271 publicly known?
Yes, CVE-2012-0271 is a publicly disclosed vulnerability and should be addressed promptly to mitigate risk.