Buffer Overflow Vulnerability in Novell GroupWise Messenger and Novell Messenger
CVE-2013-1085

Currently unrated

Key Information:

Vendor

Novell

Vendor
CVE Published:
29 March 2013

What is CVE-2013-1085?

A stack-based buffer overflow exists in the nim: protocol handler of Novell GroupWise Messenger and Novell Messenger versions prior to 2.2.2. An attacker can exploit this vulnerability by sending an import command that contains an excessively long filename parameter, allowing them to execute arbitrary code on the affected system remotely. This poses a significant security risk for users running the vulnerable versions.

References

EPSS Score

26% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.