This application requires Javascript for optimal performance.

Novell.GroupWise.iCal.RRULE.Time.Conversion.Invalid.Array.Index

Release Date

Oct 21, 2011

Severity

critical

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attack attempt against a Memory Corruption vulnerability in Novell GroupWise Internet Agent.

The vulnerability is caused by an error when the vulnerable software handles an "iCal" file that includes a malicious parameter. It may allow remote attackers to execute arbitrary code by sending a crafted "iCal" file.

Affected Products

Novell Groupwise prior to 8.02 HP3

Recommended Actions

Apply fixes or patches from the vendor, available from the website:
http://www.novell.com/support/viewContent.do?externalId=7009216

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2011-2663

Reference/s


Reference: VID-29500