Messenger Agents (nmma.exe) in Novell GroupWise 2.0.2 and 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted HTTP POST request to TCP port 8300 with a modified val parameter, which triggers a null dereference related to zero-size strings in blowfish routines.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Groupwise_messenger | Novell | 1.0.6 (including) | 1.0.6 (including) |
Groupwise_messenger | Novell | 2.0.2 (including) | 2.0.2 (including) |