CVE-2012-0439

An ActiveX control in gwcls1.dll in the client in Novell GroupWise 8.0 before 8.0.3 HP2 and 2012 before SP1 HP1 allows remote attackers to execute arbitrary code via (1) a pointer argument to the SetEngine method or (2) an XPItem pointer argument to an unspecified method.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:novell:groupwise:8.0:*:*:*:*:*:*:*
cpe:2.3:a:novell:groupwise:8.00:hp1:*:*:*:*:*:*
cpe:2.3:a:novell:groupwise:8.00:hp2:*:*:*:*:*:*
cpe:2.3:a:novell:groupwise:8.00:hp3:*:*:*:*:*:*
cpe:2.3:a:novell:groupwise:8.01:*:*:*:*:*:*:*
cpe:2.3:a:novell:groupwise:8.01:hp:*:*:*:*:*:*
cpe:2.3:a:novell:groupwise:8.02:*:*:*:*:*:*:*
cpe:2.3:a:novell:groupwise:8.02:hp1:*:*:*:*:*:*
cpe:2.3:a:novell:groupwise:8.02:hp2:*:*:*:*:*:*
cpe:2.3:a:novell:groupwise:8.02:hp3:*:*:*:*:*:*
cpe:2.3:a:novell:groupwise:8.03:*:*:*:*:*:*:*
cpe:2.3:a:novell:groupwise:8.03:hp1:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:novell:groupwise:2012:*:*:*:*:*:*:*
cpe:2.3:a:novell:groupwise:2012:sp1:*:*:*:*:*:*

History

21 Nov 2024, 01:34

Type Values Removed Values Added
References () http://www.novell.com/support/kb/doc.php?id=7011688 - Vendor Advisory () http://www.novell.com/support/kb/doc.php?id=7011688 - Vendor Advisory
References () http://www.zerodayinitiative.com/advisories/ZDI-13-008/ - () http://www.zerodayinitiative.com/advisories/ZDI-13-008/ -
References () https://bugzilla.novell.com/show_bug.cgi?id=712144 - () https://bugzilla.novell.com/show_bug.cgi?id=712144 -
References () https://bugzilla.novell.com/show_bug.cgi?id=743674 - () https://bugzilla.novell.com/show_bug.cgi?id=743674 -

Information

Published : 2013-02-24 04:37

Updated : 2024-11-21 01:34


NVD link : CVE-2012-0439

Mitre link : CVE-2012-0439

CVE.ORG link : CVE-2012-0439


JSON object : View

Products Affected

novell

  • groupwise
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')