CVE-2009-0410 Information

Description

Off-by-one error in the SMTP daemon in GroupWise Internet Agent (GWIA) in Novell GroupWise 6.5x 7.0 7.01 7.02 7.03 7.03HP1a and 8.0 allows remote attackers to execute arbitrary code via a long e-mail address in a malformed RCPT command leading to a buffer overflow.

Reference

http://download.novell.com/Download?buildid=GjZRRdqCFW0 http://secunia.com/advisories/33744 http://www.novell.com/support/viewContent.do?externalId=7002502 http://www.securityfocus.com/archive/1/500609/100/0/threaded http://www.securityfocus.com/bid/33560 http://www.zerodayinitiative.com/advisories/ZDI-09-010/

Share on: