Vulnerability Name:

CVE-2013-0804 (CCN-81708)

Assigned:2013-01-30
Published:2013-01-30
Updated:2013-02-25
Summary:The client in Novell GroupWise 8.0 before 8.0.3 HP2 and 2012 before SP1 HP1 allows remote attackers to execute arbitrary code or cause a denial of service (incorrect pointer dereference) via unspecified vectors.
CVSS v3 Severity:10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
7.4 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
9.3 High (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C)
6.9 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-78
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2013-0804

Source: CCN
Type: SA52031
Novell GroupWise Client Two Vulnerabilities

Source: CCN
Type: Novell Document ID: 7011687
GroupWise Client for Windows Remote Untrusted Pointer Dereference Vulnerability

Source: CONFIRM
Type: Vendor Advisory
http://www.novell.com/support/kb/doc.php?id=7011687

Source: CCN
Type: BID-57657
Novell Groupwise Client CVE-2013-0804 Multiple Remote Code Execution Vulnerabilities

Source: CONFIRM
Type: UNKNOWN
https://bugzilla.novell.com/show_bug.cgi?id=792535

Source: XF
Type: UNKNOWN
groupwise-pointers-code-exec(81708)

Source: MISC
Type: UNKNOWN
https://www.htbridge.com/advisory/HTB23131

Vulnerable Configuration:Configuration 1:
  • cpe:/a:novell:groupwise:8.0:*:*:*:*:*:*:*
  • OR cpe:/a:novell:groupwise:8.00:hp1:*:*:*:*:*:*
  • OR cpe:/a:novell:groupwise:8.00:hp2:*:*:*:*:*:*
  • OR cpe:/a:novell:groupwise:8.00:hp3:*:*:*:*:*:*
  • OR cpe:/a:novell:groupwise:8.01:*:*:*:*:*:*:*
  • OR cpe:/a:novell:groupwise:8.01:hp:*:*:*:*:*:*
  • OR cpe:/a:novell:groupwise:8.02:*:*:*:*:*:*:*
  • OR cpe:/a:novell:groupwise:8.02:hp1:*:*:*:*:*:*
  • OR cpe:/a:novell:groupwise:8.02:hp2:*:*:*:*:*:*
  • OR cpe:/a:novell:groupwise:8.02:hp3:*:*:*:*:*:*
  • OR cpe:/a:novell:groupwise:8.03:*:*:*:*:*:*:*
  • OR cpe:/a:novell:groupwise:8.03:hp1:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/a:novell:groupwise:2012:*:*:*:*:*:*:*
  • OR cpe:/a:novell:groupwise:2012:sp1:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:novell:groupwise:8.0:*:*:*:*:*:*:*
  • OR cpe:/a:novell:groupwise:8.0:hp1:*:*:*:*:*:*
  • OR cpe:/a:novell:groupwise:8.0:hp2:*:*:*:*:*:*
  • OR cpe:/a:novell:groupwise:8.0:sp1:*:*:*:*:*:*
  • OR cpe:/a:novell:groupwise:8.01:*:*:*:*:*:*:*
  • OR cpe:/a:novell:groupwise:8.02:*:*:*:*:*:*:*
  • OR cpe:/a:novell:groupwise:8.02:hp3:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    novell groupwise 8.0
    novell groupwise 8.00 hp1
    novell groupwise 8.00 hp2
    novell groupwise 8.00 hp3
    novell groupwise 8.01
    novell groupwise 8.01 hp
    novell groupwise 8.02
    novell groupwise 8.02 hp1
    novell groupwise 8.02 hp2
    novell groupwise 8.02 hp3
    novell groupwise 8.03
    novell groupwise 8.03 hp1
    novell groupwise 2012
    novell groupwise 2012 sp1
    novell groupwise 8.0
    novell groupwise 8.0 hp1
    novell groupwise 8.0 hp2
    novell groupwise 8.0 sp1
    novell groupwise 8.01
    novell groupwise 8.02
    novell groupwise 8.02 hp3