>> Novell GroupWise Messenger Blowfish Routines Denial of Service Vulnerability
Title : Novell GroupWise Messenger Blowfish Routines Denial of Service Vulnerability VUPEN ID : VUPEN/ADV-2006-3893 CVE ID : CVE-2006-4511
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-10-03
Technical Description
A vulnerability has been identified in Novell GroupWise Messenger, which could be exploited by attackers to cause a denial of service. This flaw is due to a NULL pointer dereference error in the blowfish routines when handling zero-sized strings, which could be exploited by attackers to crash a vulnerable service via a specially crafted HTTP request (port 8300/tcp) with a modified "val" parameter.