Novell GroupWise Internet Agent (GWIA) - Security Vulnerability Processing SMTP Requests
This document (7003272) is provided subject to the disclaimer at the end of this document.
Environment
GroupWise Internet Agent
GroupWise 7.0 up to (and including) 7.03 HP2
GroupWise 8.0 up to (and including) 8.0.0 HP1
GroupWise 7.0 up to (and including) 7.03 HP2
GroupWise 8.0 up to (and including) 8.0.0 HP1
Situation
A vulnerability exists in Novell GroupWise Internet Agent, in the way it processes certain SMTP requests. Exploitation of this vulnerability could lead to arbitrary code execution with SYSTEM privileges.
This vulnerability was discovered and reported by Nicolas Joly - VUPEN Security (http://www.vupen.com / VUPEN-SR-2009-001).
Novell bug 478892, CVE-2009-1636.
This vulnerability was discovered and reported by Nicolas Joly - VUPEN Security (http://www.vupen.com / VUPEN-SR-2009-001).
Novell bug 478892, CVE-2009-1636.
Resolution
To resolve this issue:
For GroupWise 7.x systems, apply GroupWise 7.03 Hot Patch 3 (HP3) or later
For GroupWise 8.0 systems, apply GroupWise 8.0 Hot Patch 2 (HP2) or later
For GroupWise 7.x systems, apply GroupWise 7.03 Hot Patch 3 (HP3) or later
For GroupWise 8.0 systems, apply GroupWise 8.0 Hot Patch 2 (HP2) or later
Status
Security AlertBug Number
478892
Disclaimer
This Support Knowledgebase provides a valuable tool for NetIQ/Novell/SUSE customers and parties interested in our products and solutions to acquire information, ideas and learn from one another. Materials are provided for informational, personal or non-commercial use within your organization and are presented "AS IS" WITHOUT WARRANTY OF ANY KIND.
- Document ID:7003272
- Creation Date:14-MAY-09
- Modified Date:15-JAN-13
- NovellGroupWise
Did this document solve your problem? Provide Feedback
