Check Point Reference: | CPAI-2011-563 |
Date Published: | 6 Dec 2011 |
Severity: | Critical |
Last Updated: | Saturday 01 January, 2011 |
Source: | |
Industry Reference: | CVE-2011-2662 |
Protection Provided by: | |
Who is Vulnerable? | Novell Groupwise prior to 8.02 HP3 |
Vulnerability Description | A remote code injection and execution vulnerability has been reported in Novell GroupWise Internet Agent (GWIA). |
Vulnerability Details | The vulnerability is due to a boundary error in the Novell GroupWise Internet Agent while parsing an RRULE variable of a VCALENDAR inside an email message. A remote attacker could exploit this issue by sending a malicious email to the target server. Successful exploitation of this vulnerability could result in arbitrary code injection and execution on an affected system. |