CVE-2012-0271

Novell GroupWise <8.0.3-2012.SP1 - RCE

Title source: llm

Description

Integer overflow in the WebConsole component in gwia.exe in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before 8.0.3 HP1 and 2012 before SP1 might allow remote attackers to execute arbitrary code via a crafted request that triggers a heap-based buffer overflow, as demonstrated by a request with -1 in the Content-Length HTTP header.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Francis Provencher · textdoswindows
https://www.exploit-db.com/exploits/21326

Scores

EPSS 0.3326
EPSS Percentile 96.8%

Classification

CWE
CWE-189
Status draft

Affected Products (43)

novell/groupwise
novell/groupwise
novell/groupwise
novell/groupwise
novell/groupwise
novell/groupwise
novell/groupwise
novell/groupwise
novell/groupwise
novell/groupwise
novell/groupwise
novell/groupwise
novell/groupwise
novell/groupwise
novell/groupwise
... and 28 more

Timeline

Published Sep 19, 2012
Tracked Since Feb 18, 2026