This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Novell multiple vulns - updates available

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://www.us-cert.gov/current/current_act…ctory_version_8
October 6, 2008 - "Novell has released eDirectory 8.7.3 SP10 FTF1 to address multiple vulnerabilities. These vulnerabilities may allow an attacker to execute arbitrary code or cause a denial-of-service condition on the affected system. US-CERT encourages users to review Novell document 3477912* and apply any necessary patches** to help mitigate the risks."

Environment: Novell eDirectory 8.7.3 for All Platforms
Situation: History of Issues resolved…
* http://www.novell.com/support/viewContent….ernalId=3477912

Novell Downloads:
** http://preview.tinyurl.com/4y39rp

:ph34r:
FYI…

Novell releases updates for GroupWise
- http://www.us-cert.gov/current/#novell_rel…s_for_groupwise
January 30, 2009 - "Novell has released updates for GroupWise 7 and 8 to address multiple vulnerabilities. These vulnerabilities may allow an attacker to execute arbitrary code, compromise a GroupWise account, conduct cross-site scripting attacks, or obtain sensitive information. US-CERT encourages users to review the Novell download page* and apply the appropriate patch to help mitigate the risks."
* http://preview.tinyurl.com/4et673

- http://secunia.com/advisories/33744/
Release Date: 2009-02-02
Critical: Highly critical
Impact: Security Bypass, Cross Site Scripting, DoS, System access
Where: From remote
Solution Status: Vendor Patch…

- http://web.nvd.nist.gov/view/vuln/detail?v…d=CVE-2009-0272
- http://web.nvd.nist.gov/view/vuln/detail?v…d=CVE-2009-0273
- http://web.nvd.nist.gov/view/vuln/detail?v…d=CVE-2009-0274
- http://web.nvd.nist.gov/view/vuln/detail?v…d=CVE-2009-0410

:ph34r:
FYI…

Novell GroupWise multiple vulns - updates available
- http://secunia.com/advisories/35177/2/
Release Date: 2009-05-22
Critical: Highly critical
Impact: Security Bypass, Cross Site Scripting, DoS, System access
Where: From remote
Solution Status: Vendor Patch
Software: Novell GroupWise 7.x, Novell GroupWise 8.x …
Solution: Apply 7.03 HP3 or 8.0 HP2.
Original Advisory: Novell:
http://www.novell.com/support/viewContent….ernalId=7003266
http://www.novell.com/support/viewContent….ernalId=7003267
http://www.novell.com/support/viewContent….ernalId=7003268
http://www.novell.com/support/viewContent….ernalId=7003271
http://www.novell.com/support/viewContent….ernalId=7003272
http://www.novell.com/support/viewContent….ernalId=7003273 …

- http://www.us-cert.gov/current/#novell_rel…_for_groupwise1
May 22, 2009

:ph34r: