Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Stack-based buffer overflow in the base64_decode function in GWINTER.exe in Novell GroupWise (GW) WebAccess before 7.0 SP2 allows remote attackers to execute arbitrary code via long base64 content in an HTTP Basic Authentication request.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Novell Groupwise WebAccess GWINTER.EXE远程栈缓冲区溢出漏洞
Vulnerability Description
Novell Groupwise WebAccess是一款基于WEB的邮件、日程表、通讯录解决方案。 WebAccess中默认绑定到TCP 7205和7211端口上的GWINTER.exe进程存在栈溢出漏洞,远程攻击者可能利用此漏洞控制服务器。 在处理HTTP Basic认证请求时这个进程会将用户提供的base64数据拷贝到固定长度的栈缓冲区,由于base64_decode()调用中的漏洞攻击者发送336字节就可以触发栈溢出,导致执行任意指令。
CVSS Information
N/A
Vulnerability Type
N/A