RULE(RULE ID:323012)

Rule General Information
Release Date: 2019-06-27
Rule Name: Novell Groupwise Internet Agent Content Length Buffer Overflow Vulnerability (CVE-2012-0271)
Severity:
CVE ID:
Rule Protection Details
Description: Integer overflow in the WebConsole component in gwia.exe in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before 8.0.3 HP1 and 2012 before SP1 might allow remote attackers to execute arbitrary code via a crafted request that triggers a heap-based buffer overflow, as demonstrated by a request with -1 in the Content-Length HTTP header.
Impact: A buffer overflow vulnerability can be triggered by an attacker in the context of the vulnerable product. Further attacks includes arbitrary code execution and denial of service.
Affected OS: Windows, Linux, FreeBSD, Solaris, Other Unix, Network Device, Mac OS, iOS, Android, Others
Reference: http://www.novell.com/support/kb/doc.php?id=7010769
http://www.protekresearchlab.com/index.php?option=com_content&view=article&id=61&Itemid=61
https://bugzilla.novell.com/show_bug.cgi?id=746199
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
http://www.novell.com/support/kb/doc.php?id=7010769