10
CVSSv2

CVE-2010-4711

Published: 31/01/2011 Updated: 26/04/2011
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Double free vulnerability in the IMAP server component in GroupWise Internet Agent (GWIA) in Novell GroupWise prior to 8.02HP allows remote malicious users to execute arbitrary code via a large parameter in a LIST command.

Vulnerable Product Search on Vulmon Subscribe to Product

novell groupwise 5.57e

novell groupwise 6.0

novell groupwise 6.0.1

novell groupwise 6.5

novell groupwise 7.0

novell groupwise 7.0.2

novell groupwise 7.0.3

novell groupwise 4.1a

novell groupwise 5.1

novell groupwise 5.5

novell groupwise 6.5.2

novell groupwise 7.0.4

novell groupwise 8.0

novell groupwise

novell groupwise 5.2

novell groupwise 4.1

novell groupwise 6.5.4

novell groupwise 6.5.6

novell groupwise 6.5.7

novell groupwise 5.0

novell groupwise 6.5.3

novell groupwise 7.0.1

novell groupwise 8.0.1

Exploits

##################################################################################### Application: {PRL} Novell Groupwise Internet Agent IMAP LIST Command Remote Code Execution Vulnerability Platforms: Linux Exploitation: Remote code execution CVE Number: Pending Novell TID: 7007151 ZeroDayInitiative: ZDI-10-242 Author: Francis Prov ...