CVE-2012-0271

critical
Published 2012-09-19 · Modified 2026-04-29
CVSS v3
CVSS v2
10.0
VIR risk
10.0

Description

Integer overflow in the WebConsole component in gwia.exe in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before 8.0.3 HP1 and 2012 before SP1 might allow remote attackers to execute arbitrary code via a crafted request that triggers a heap-based buffer overflow, as demonstrated by a request with -1 in the Content-Length HTTP header.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: PSIRT-CNA@flexerasoftware.com — http://www.novell.com/support/kb/doc.php?id=7010769

Application impact

VendorProductVersionsFixed
novellgroupwise8.0
novellgroupwise8.01
novellgroupwise8.02
novellgroupwise8.03
novellgroupwise2012
novellgroupwise5.2
novellgroupwise5.5
novellgroupwise5.57e
novellgroupwise6.0
novellgroupwise6.0.1
novellgroupwise6.5
novellgroupwise6.5.2
novellgroupwise6.5.3
novellgroupwise6.5.4
novellgroupwise6.5.6
novellgroupwise6.5.7
novellgroupwise7.0
novellgroupwise7.0.3
novellgroupwise7.0.4
novellgroupwise7.01
novellgroupwise7.02
novellgroupwise7.03

References

CWEs

CWE-189

Verify integrity in audit chain (admin only). AS-IS.