VID |
23164 |
Severity |
40 |
Port |
8300 |
Protocol |
TCP |
Class |
WWW |
Detailed Description |
The Novell Messenger Messaging Agent is vulnerable to a buffer overflow vulnerability via the 'Accept-Language' header. Novell Messenger Messaging Agent is an enterprise instant messaging server for Microsoft Windows, Linux, and Novell Netware platforms. Novell GroupWise Messenger version 2.0 is vulnerable to a stack-based buffer overflow vulnerability via a long Accept-Language value without a comma or semicolon. By sending a specially-crafted HTTP request containing an overly long Accept-Language header to TCP port 8300, a remote attacker could exploit this vulnerability to execute arbitrary code on the affected host.
* References: http://support.novell.com/cgi-bin/search/searchtid.cgi?10100861.htm http://www.zerodayinitiative.com/advisories/ZDI-06-008.html http://lists.grok.org.uk/pipermail/full-disclosure/2006-April/045075.html http://www.milw0rm.com/exploits/1679
* Platforms Affected: Novell Groupwise Messenger version 2.0 Microsoft Windows Any version Novell NetWare Any version Linux Any version |
Recommendation |
Upgrade to the latest version of Novell GroupWise Messenger (2.0 Public Beta 2 or later), as listed in Novell Technical Information Document TID10100861 at http://support.novell.com/cgi-bin/search/searchtid.cgi?10100861.htm |
Related URL |
CVE-2006-0992 (CVE) |
Related URL |
17503 (SecurityFocus) |
Related URL |
25828 (ISS) |
|