CVE-2011-4189

Novell GroupWise 8.0x-8.02HP3 - Remote Code Execution via Long Email Address in Address Book File

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2011-4189. PoCs published by Francis Provencher.

AI-analyzed exploit summary This exploit leverages a buffer overflow vulnerability in Novell Groupwise Client by crafting a malformed Novell Address Book (*.NAB) file with an overly long email address. The exploit triggers remote code execution when the user opens the malicious file.

Description

The client in Novell GroupWise 8.0x through 8.02HP3 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption and application crash) via a long e-mail address in an Address Book (aka .NAB) file.

Exploits (1)

exploitdb WORKING POC
by Francis Provencher · textdoswindows
https://www.exploit-db.com/exploits/18546

This exploit leverages a buffer overflow vulnerability in Novell Groupwise Client by crafting a malformed Novell Address Book (*.NAB) file with an overly long email address. The exploit triggers remote code execution when the user opens the malicious file.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Novell Groupwise Client
No auth needed
Prerequisites: User interaction required to open the malicious *.NAB file
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/79720
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/73588
Issue Tracking x_refsource_confirm
https://bugzilla.novell.com/show_bug.cgi?id=733885
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/52233
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/48199
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1026753

Scores

EPSS 0.1174
EPSS Percentile 95.5%

Details

CWE
CWE-94
Status published
Products (3)
novell/groupwise 8.0 (4 CPE variants)
novell/groupwise 8.0.1
novell/groupwise 8.0.2 (2 CPE variants)
Published Mar 02, 2012
Tracked Since Feb 18, 2026