CVE-2011-0333
published 2011-10-08CVE-2011-0333: Heap-based buffer overflow in the NgwiCalVTimeZoneBody::ParseSelf function in gwwww1.dll in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3…
PriorityP346critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
6.12%
92.6th percentile
Heap-based buffer overflow in the NgwiCalVTimeZoneBody::ParseSelf function in gwwww1.dll in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to execute arbitrary code via a crafted TZNAME variable in a VCALENDAR attachment in an e-mail message, related to an "integer truncation error."
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| novell | groupwise | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat6.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gx9r-3crr-q2qw: Heap-based buffer overflow in the NgwiCalVTimeZoneBody::ParseSelf function in gwwww1
ghsa_unreviewed·2022-05-17
CVE-2011-0333 [HIGH] CWE-119 GHSA-gx9r-3crr-q2qw: Heap-based buffer overflow in the NgwiCalVTimeZoneBody::ParseSelf function in gwwww1
Heap-based buffer overflow in the NgwiCalVTimeZoneBody::ParseSelf function in gwwww1.dll in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to execute arbitrary code via a crafted TZNAME variable in a VCALENDAR attachment in an e-mail message, related to an "integer truncation error."
Red Hat
kernel: possible privilege escalation via SG_IO ioctl
vendor_redhat·2011-12-22·CVSS 4.6
CVE-2011-4127 [MEDIUM] CWE-284 kernel: possible privilege escalation via SG_IO ioctl
kernel: possible privilege escalation via SG_IO ioctl
The Linux kernel before 3.2.2 does not properly restrict SG_IO ioctl calls, which allows local users to bypass intended restrictions on disk read and write operations by sending a SCSI command to (1) a partition block device or (2) an LVM volume.
Statement: This issue affects the Linux kernel as shipped with Red Hat Enterprise Linux 4,
5, 6, and Red Hat Enterprise MRG. This has been addressed in Red Hat Enterprise Linux 5, 6, and Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2012-0107.html, https://rhn.redhat.com/errata/RHSA-2011-1849.html, and https://rhn.redhat.com/errata/RHSA-2012-0333.html. Red Hat Enterprise Linux 4 is now in Production 3 of the maintenance life-cycle, https://access.redhat.com/support/policy/upda
Red Hat
kernel: nfs4_getfacl decoding kernel oops
vendor_redhat·2011-11-05·CVSS 4.6
CVE-2011-4131 [MEDIUM] kernel: nfs4_getfacl decoding kernel oops
kernel: nfs4_getfacl decoding kernel oops
The NFSv4 implementation in the Linux kernel before 3.2.2 does not properly handle bitmap sizes in GETACL replies, which allows remote NFS servers to cause a denial of service (OOPS) by sending an excessive number of bitmap words.
Statement: This issue does not affect the Linux kernel as shipped with Red Hat Enterprise Linux 4 as it does not provide support for NFS ACLs. This issue does not affect the Linux kernel as shipped with Red Hat Enterprise Linux 5. This has been addressed in Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2012-0333.html. Future kernel updates in Red Hat Enterprise Linux 6 may address this issue.
Package: kernel (Red Hat Enterprise Linux 4) - Not affected
Package: kernel (Red Hat Enterprise Linux 5) - Not
Red Hat
kernel: oom_badness() integer overflow
vendor_redhat·2011-10-31·CVSS 5.5
CVE-2011-4097 [MEDIUM] CWE-190 kernel: oom_badness() integer overflow
kernel: oom_badness() integer overflow
Integer overflow in the oom_badness function in mm/oom_kill.c in the Linux kernel before 3.1.8 on 64-bit platforms allows local users to cause a denial of service (memory consumption or process termination) by using a certain large amount of memory.
Statement: This issue did not affect the Linux kernel as shipped with Red Hat Enterprise Linux 4, 5, and 6 as they did not backport the upstream commit f755a04 that introduced this. This has been addressed in Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2012-0333.html.
Package: kernel (Red Hat Enterprise Linux 4) - Not affected
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Affected
Red Hat
kernel: perf: Fix software event overflow
vendor_redhat·2011-07-22·CVSS 5.5
CVE-2011-2918 [MEDIUM] kernel: perf: Fix software event overflow
kernel: perf: Fix software event overflow
The Performance Events subsystem in the Linux kernel before 3.1 does not properly handle event overflows associated with PERF_COUNT_SW_CPU_CLOCK events, which allows local users to cause a denial of service (system hang) via a crafted application.
Statement: This issue did not affect Red Hat Enterprise Linux 4 and 5 as they did not include support for perf. This has been addressed in Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2011-1350.html and https://rhn.redhat.com/errata/RHSA-2012-0333.html.
Package: kernel (Red Hat Enterprise Linux 4) - Not affected
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Red Hat
kernel: xfs: potential buffer overflow in xfs_readlink()
vendor_redhat·2011-04-08·CVSS 6.9
CVE-2011-4077 [MEDIUM] kernel: xfs: potential buffer overflow in xfs_readlink()
kernel: xfs: potential buffer overflow in xfs_readlink()
Buffer overflow in the xfs_readlink function in fs/xfs/xfs_vnodeops.c in XFS in the Linux kernel 2.6, when CONFIG_XFS_DEBUG is disabled, allows local users to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code via an XFS image containing a symbolic link with a long pathname.
Statement: This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 4 as it did not include support for XFS filesystem. This has been addressed in Red Hat Enterprise Linux 5, 6 and Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2012-0007.html, https://rhn.redhat.com/errata/RHSA-2012-0350.html, and https://rhn.redhat.com/errata/RHSA-2012-0333.html.
Package: kernel (Re
No detection rules found.
http://secunia.com/secunia_research/2011-66/http://www.novell.com/support/viewContent.do?externalId=7009208https://bugzilla.novell.com/show_bug.cgi?id=678715https://labs.idefense.com/verisign/intelligence/2009/vulnerabilities/display.php?id=943http://secunia.com/secunia_research/2011-66/http://www.novell.com/support/viewContent.do?externalId=7009208https://bugzilla.novell.com/show_bug.cgi?id=678715https://labs.idefense.com/verisign/intelligence/2009/vulnerabilities/display.php?id=943
2011-10-08
Published