CVE-2011-3827

Novell GroupWise < 8.00 - Denial of Service via Crafted iCalendar Date-Time String

Title source: llm
STIX 2.1

Description

The iCalendar component in gwwww1.dll in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before Support Pack 3 allows remote attackers to cause a denial of service (out-of-bounds read and daemon crash) via a crafted date-time string in a .ics attachment.

References (5)

Core 5
Core References
Vendor Advisory x_refsource_confirm
http://www.novell.com/support/kb/doc.php?id=7010767
Vendor Advisory x_refsource_misc
http://secunia.com/secunia_research/2012-30/
Third Party Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2012-09/0075.html
Issue Tracking x_refsource_confirm
https://bugzilla.novell.com/show_bug.cgi?id=733887
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1027540

Scores

EPSS 0.0365
EPSS Percentile 88.0%

Details

CWE
CWE-119
Status published
Products (3)
novell/groupwise 8.0
novell/groupwise 8.00 hp1 (2 CPE variants)
novell/groupwise < 8.00
Published Sep 19, 2012
Tracked Since Feb 18, 2026