Vulnerability Note VU#919369
Novell Netmail WebAdmin buffer overflow vulnerability
OverviewNovell NetMail contains a buffer overflow vulnerability that may allow an attacker to execute arbitrary code.
I. DescriptionNovell NetMail is an email and messenging software package developed by Novell. It is designed to offer mail and calendaring services to large groups of users.
WebAdmin is a browser based administrative tool used to manage NetMail. WebAdmin (webadmin.exe) contains a buffer overflow vulnerability. An attacker may be able to trigger the overflow by sending an oversized username to the WebAdmin interface on a vulnerable system.
II. ImpactA remote, unathenticated attacker may be able to execute arbitrary code.
III. SolutionUpdate
Novell has released NetMail 3.52e to address this issue.
Restrict access
Restricting access to port 89/tcp and 449/tcp to trusted hosts may mitigate this vulnerability.
Systems Affected
| Vendor | Status | Date Notified | Date Updated |
| Novell, Inc. | Vulnerable | 8-Mar-2007 |
References
http://download.novell.com/Download?buildid=sMYRODW09pw
http://www.novell.com/products/netmail/
http://www.novell.com/documentation/netmail35/index.html?page=/documentation/netmail35/netmail35/data/bou06jd.html
http://www.zerodayinitiative.com/advisories/ZDI-07-009.html
http://secunia.com/advisories/24445/
http://www.ciac.org/ciac/bulletins/r-173.shtml
http://www.securityfocus.com/bid/22857
http://securitytracker.com/id?1017734
Credit
Thanks to the Zero Day Initiative for providing information about this vulnerability.
This document was written by Ryan Giobbi.
Other Information
| Date Public: | 2007-03-07 |
| Date First Published: | 2007-03-08 |
| Date Last Updated: | 2007-03-19 |
| CERT Advisory: | |
| CVE-ID(s): | CVE-2007-1350 |
| NVD-ID(s): | CVE-2007-1350 |
| US-CERT Technical Alerts: | |
| Metric: | 3.04 |
| Document Revision: | 19 |
If you have feedback, comments, or additional information about this vulnerability, please send us
email.
|