CVE-2010-4714
Multiple stack-based buffer overflows in Novell GroupWise before 8.02HP allow remote attackers to execute arbitrary code via a long HTTP Host header to (1) gwpoa.exe in the Post Office Agent, (2) gwmta.exe in the Message Transfer Agent, (3) gwia.exe in…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (6.12%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple stack-based buffer overflows in Novell GroupWise before 8.02HP allow remote attackers to execute arbitrary code via a long HTTP Host header to (1) gwpoa.exe in the Post Office Agent, (2) gwmta.exe in the Message Transfer Agent, (3) gwia.exe in the Internet Agent, (4) the WebAccess Agent, or (5) the Monitor Agent.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 6.12% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- novell/groupwise
- Source
- cve@mitre.org
References
- http://www.facebook.com/note.php?note_id=477865030928
- http://www.novell.com/support/viewContent.do?externalId=7007159&sliceId=1Vendor Advisory
- http://zerodayinitiative.com/advisories/ZDI-10-247/
- https://bugzilla.novell.com/show_bug.cgi?id=627942
- http://www.facebook.com/note.php?note_id=477865030928
- http://www.novell.com/support/viewContent.do?externalId=7007159&sliceId=1Vendor Advisory
- http://zerodayinitiative.com/advisories/ZDI-10-247/
- https://bugzilla.novell.com/show_bug.cgi?id=627942
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.