CVE-2013-0804: OS Command Injection
Published Feb 24, 2013
·Updated
The client in Novell GroupWise 8.0 before 8.0.3 HP2 and 2012 before SP1 HP1 allows remote attackers to execute arbitrary code or cause a denial of service (incorrect pointer dereference) via unspecified vectors.
Affected Software
14 affected components
Novell GroupWise=8.0
Novell GroupWise=8.00-hp1
Novell GroupWise=8.00-hp2
Novell GroupWise=8.00-hp3
Novell GroupWise=8.01
Novell GroupWise=8.01-hp
Novell GroupWise=8.02
Novell GroupWise=8.02-hp1
Novell GroupWise=8.02-hp2
Novell GroupWise=8.02-hp3
Novell GroupWise=8.03
Novell GroupWise=8.03-hp1
Novell GroupWise=2012
Novell GroupWise=2012-sp1
Event History
Feb 24, 2013
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-0804?
CVE-2013-0804 is considered to have a high severity due to its potential for remote code execution and denial of service.
2
How do I fix CVE-2013-0804?
To fix CVE-2013-0804, you should upgrade to Novell GroupWise 8.0.3 HP2 or later versions.
3
What versions of Novell GroupWise are affected by CVE-2013-0804?
CVE-2013-0804 affects Novell GroupWise 8.0, all HP versions prior to 8.0.3 HP2, and the 2012 version prior to SP1 HP1.
4
Can CVE-2013-0804 be exploited without user interaction?
Yes, CVE-2013-0804 can be exploited remotely without user interaction.
5
What type of attack can be performed using CVE-2013-0804?
Attackers can exploit CVE-2013-0804 to execute arbitrary code or create a denial of service through incorrect pointer dereference.