Stack-based Buffer Overflow in Novell GroupWise Messenger
CVE-2006-0992
Currently unrated
Key Information:
- Vendor
Novell
- Status
- Vendor
- CVE Published:
- 14 April 2006
Badges
๐พ Exploit Exists๐ก Public PoC๐ฃ EPSS 88%
What is CVE-2006-0992?
A vulnerability exists in Novell GroupWise Messenger that allows remote attackers to exploit a stack-based buffer overflow. This occurs when an unusually long Accept-Language header value, which lacks a comma or semicolon, is processed. An attacker can leverage this flaw to execute arbitrary code on the affected system, potentially compromising its security. Proper input validation and code handling measures are crucial to mitigate this risk.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.