Integer overflow in the Post Office Agent in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 might allow remote attackers to execute arbitrary code via a long (1) username or (2) password, which triggers a heap-based buffer overflow.
2017-04-20T17:59:00.507
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 9.8 (CRITICAL)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | novell | groupwise | ≤ 2012 | Yes |
| Application | novell | groupwise | 2014 | Yes |
| Application | novell | groupwise | 2014 | Yes |
| Application | novell | groupwise | 2014 | Yes |
| Application | novell | groupwise | 2014 | Yes |