Novell GroupWise WebAccess Agent Authentication Remote Code Execution Vulnerability


Description   A vulnerability has been identified in Novell GroupWise, which could be exploited by attackers to remotely take complete control of an affected system. This issue is caused by a stack overflow error in the WebAccess agent (GWINTER.exe) when processing an overly long (more than 335 bytes) HTTP Basic authentication request sent to port 7205/TCP or 7211/TCP, which could be exploited by remote unauthenticated attackers to execute arbitrary commands with elevated privileges by sending specially crafted base64 data to a vulnerable application.
     
Vulnerable Products   Vulnerable Software:
Novell GroupWise versions 7.x
     
Solution   Upgrade to Novell GroupWise version 7.0.2 (for Windows and Netware) : http://download.novell.com/protected/Export.jsp?buildid=8RF83go0nZg~Upgrade to Novell GroupWise version 7.0.2 (for Linux) : http://download.novell.com/protected/Export.jsp?buildid=O9ucpbS1bK0~
     
CVE   CVE-2007-2171
     
References   http://download.novell.com/Download?buildid=8RF83go0nZg~
http://download.novell.com/Download?buildid=O9ucpbS1bK0~
http://www.zerodayinitiative.com/advisories/ZDI-07-015.html
     
Vulnerability Manager Detection   No
     
IPS Protection  
ASQ Engine alarm Available Since
Possible buffer overflow in HTTP request/reply
3.2.0
     


 
 
 
 
 Risk level 
Critical 

 Vulnerability First Public Report Date 
2007-04-18 

 Target Type 
Server 

 Possible exploit 
Local & Remote