Title : Novell GroupWise WebAccess Agent Authentication Remote Code Execution Vulnerability VUPEN ID : VUPEN/ADV-2007-1455 CVE ID : CVE-2007-2171
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-04-18
Technical Description
A vulnerability has been identified in Novell GroupWise, which could be exploited by attackers to remotely take complete control of an affected system. This issue is caused by a stack overflow error in the WebAccess agent (GWINTER.exe) when processing an overly long (more than 335 bytes) HTTP Basic authentication request sent to port 7205/TCP or 7211/TCP, which could be exploited by remote unauthenticated attackers to execute arbitrary commands with elevated privileges by sending specially crafted base64 data to a vulnerable application.