Madrid, October 5 2006 - A vulnerability has been reported in the Novell GroupWise Messenger agents, which could allow a remote user to provoke denial of service conditions.
A remote user could crash the Messenger service by sending the target system an HTTP POST request to port 8300 with a specially modified ˝val˝ parameter. Novell has confirmed that the error lies in the processing of zero-size strings in blowfish routines.
Novell has published the patches to correct this problem:
- Para 1.0.6: http://support.novell.com/servlet/filedownload/sec/ftf/gwim106hp1.exe
- Para 2.0.2: http://support.novell.com/servlet/filedownload/sec/ftf/gwim202hp1.exe
The original Novell advisories are available at:
- http://support.novell.com/cgi-bin/search/searchtid.cgi?/2974452.htm
- http://support.novell.com/cgi-bin/search/searchtid.cgi?/2974440.htm
Oxygen3 24h-365d
by Panda Software
Back
Member of IVSZ

Member of SZEK

Acer Affinity Gold partner

Dell Registered Partner
![]()
OKI System Shinrai Partner

XEROX Viszonteladó

APC megbízható szállító

EATON Authorized Partner

Cisco partner

Symantec Software Partner

ESET Partner
![]()
FUJITSU partner

LENOVO Premium Partner

IBM Business Partner

PARTNERS: Computerworld.hu | GameStar.hu | PCWorld.hu | SG.hu | PC Guru | Hitel