Lucene search

K
saintSAINT CorporationSAINT:A531921ABE82C50588FC001F29AAF38D
HistoryApr 25, 2007 - 12:00 a.m.

Novell GroupWise WebAccess base64_decode buffer overflow

2007-04-2500:00:00
SAINT Corporation
my.saintcorporation.com
13

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

0.946 High

EPSS

Percentile

99.3%

Added: 04/25/2007
CVE: CVE-2007-2171
BID: 23556
OSVDB: 35018

Background

Novell GroupWise includes a WebAccess service which allows users to access their e-mail using a web browser.

Problem

A buffer overflow in the base64_decode function allows remote attackers to execute arbitrary commands by sending a specially crafted HTTP Basic Authentication request.

Resolution

Upgrade to Groupwise 7.0 SP2 for Windows or Linux.

References

<http://www.zerodayinitiative.com/advisories/ZDI-07-015.html&gt;

Limitations

Exploit works on Novell GroupWise 7.0.

Platforms

Windows

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

0.946 High

EPSS

Percentile

99.3%